Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michael Lappas

#14195of 53,633
18.9Total CVSS
Vulnerabilities · 3
Low
1
High
2
PT-2025-41187
7.8
2025-10-07
Anki · Anki · CVE-2025-62185
**Name of the Vulnerable Software and Affected Versions** Anki versions prior to 25.02.5 **Description** A specially designed shared deck can place a YouTube downloader executable in the media folder. This executable is then run when a YouTube link is present within the deck. The executable may be named `youtube-dl.exe`, `yt-dlp.exe`, or `yt-dlp x86.exe`. **Recommendations** Update to version 25.02.5 or later.
PT-2025-41188
7.8
2025-10-07
Microsoft · Windows · CVE-2025-62186
**Name of the Vulnerable Software and Affected Versions** Anki versions prior to 25.02.5 **Description** A specially crafted shared deck on Windows can lead to the execution of arbitrary commands when playing audio due to improper handling of URL schemes. **Recommendations** Update to version 25.02.5 or later.
PT-2025-41189
3.3
2025-10-07
Anki · Anki · CVE-2025-62187
**Name of the Vulnerable Software and Affected Versions** Anki versions prior to 25.02.6 **Description** A flaw exists in Anki that allows crafted sound file references to potentially cause files to be written to arbitrary locations on Windows and Linux systems. This occurs because media file pathnames are not necessarily relative to the media folder. **Recommendations** Update to version 25.02.6 or later.