Latest CVE Feed
-
9.6
CRITICALCVE-2025-25106
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP allows Cross Site Request Forgery. This issue affects Starter Templates by FancyWP: from n/a through 2.0.0.... Read more
Affected Products : starter_templates- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.6
CRITICALCVE-2025-24028
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handle... Read more
Affected Products : joplin- Published: Feb. 07, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2024-56347
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.... Read more
Affected Products : aix- Published: Mar. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.6
CRITICALCVE-2024-51962
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and... Read more
Affected Products : arcgis_server- Published: Mar. 03, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
9.6
CRITICALCVE-2021-2446
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc... Read more
Affected Products : secure_global_desktop- EPSS Score: %1.09
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2025-48469
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.... Read more
Affected Products : wise-4060lan_firmware wise-4060lan wise-4050lan_firmware wise-4050lan wise-4010lan_firmware wise-4010lan- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.6
CRITICALCVE-2025-32977
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. ... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Misconfiguration
-
9.6
CRITICALCVE-2024-52928
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.... Read more
- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2024-30560
Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4. ... Read more
Affected Products :- Published: Apr. 25, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2025-55733
DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any we... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
9.6
CRITICALCVE-2025-49381
Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect allows Cross Site Request Forgery. This issue affects ads.txt Guru Connect: from n/a through 1.1.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.6
CRITICALCVE-2025-4609
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)... Read more
- Published: Aug. 22, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2025-2767
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit t... Read more
Affected Products : ng_firewall- Published: Apr. 23, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-54382
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Misconfiguration
-
9.6
CRITICALCVE-2024-7760
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all e... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.6
CRITICALCVE-2025-30615
Cross-Site Request Forgery (CSRF) vulnerability in Jacob Schwartz WP e-Commerce Style Email allows Code Injection. This issue affects WP e-Commerce Style Email: from n/a through 0.6.2.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.6
CRITICALCVE-2025-50754
Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack t... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2024-52325
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
9.6
CRITICALCVE-2025-29266
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.... Read more
Affected Products : unraid- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.6
CRITICALCVE-2025-54010
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets allows Cross Site Request Forgery. This issue affects FluentSnippets: from n/a through 10.50.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Request Forgery