Latest CVE Feed
-
5.5
MEDIUMCVE-2025-48958
Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, cre... Read more
Affected Products : froxlor- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2024-45655
IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.... Read more
Affected Products : application_gateway- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20988
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-48934
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` method ignores any variables listed in the `--deny-env` option of the `deno run` command. When looking at the documentation of the `--d... Read more
Affected Products : deno- Published: Jun. 04, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-48910
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2008-0709
Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214.... Read more
- EPSS Score: %0.33
- Published: Apr. 07, 2008
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2025-5699
The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all versions up to, and including, 2015.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2023-21581
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vuln... Read more
- EPSS Score: %0.11
- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-13505
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This make... Read more
Affected Products : survey_maker- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-24814
Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authenti... Read more
Affected Products : solr- Published: Jan. 27, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2024-54519
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to read sensitive location information.... Read more
Affected Products : macos- Published: Jan. 27, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-54549
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Jan. 27, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-24151
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or corrupt kernel memory.... Read more
Affected Products : macos- Published: Jan. 27, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-23056
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary scrip... Read more
Affected Products : fabric_composer- Published: Jan. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-23057
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary scrip... Read more
Affected Products : fabric_composer- Published: Jan. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2020-8943
An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated against the requested size. The parameter size is unchecked allowing the attacke... Read more
Affected Products : asylo- EPSS Score: %0.02
- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-24791
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access t... Read more
- Published: Jan. 29, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-23007
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.... Read more
Affected Products : netextender- Published: Jan. 30, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2023-53028
In the Linux kernel, the following vulnerability has been resolved: Revert "wifi: mac80211: fix memory leak in ieee80211_if_add()" This reverts commit 13e5afd3d773c6fc6ca2b89027befaaaa1ea7293. ieee80211_if_free() is already called from free_netdev(ndev... Read more
Affected Products : linux_kernel- Published: Mar. 27, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2023-53022
In the Linux kernel, the following vulnerability has been resolved: net: enetc: avoid deadlock in enetc_tx_onestep_tstamp() This lockdep splat says it better than I could: ================================ WARNING: inconsistent lock state 6.2.0-rc2-0701... Read more
Affected Products : linux_kernel- Published: Mar. 27, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Race Condition