Latest CVE Feed
-
0.0
NONECVE-2025-34127
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-su... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34129
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
-
0.0
NONECVE-2025-49831
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53908
RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone running the latest version of RomM and has multiple users, even unprivileged user... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-6982
Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), allows attackers to decrypt the config.xml files.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-6983
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34126
A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53826
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even... Read more
Affected Products : filebrowser- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
-
0.0
NONECVE-2025-53943
VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users wit... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53938
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34118
A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unauthenticated remote attackers to read arbitrary files on the server. The vulnerability is accessible via mu... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34120
An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails to validate serialized input to the admin backup endpoint (`index.php/admin/update/sa/backup`), allowing a... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34121
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34123
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, leading to an SEH... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34117
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-34119
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. ... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53936
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to ver... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53937
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the `/controle/control.php` endpoint, specifically in the `cargo` parameter, of WeGIA prior to version... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-53935
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to ver... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-49828
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025