Latest CVE Feed
-
9.5
CRITICALCVE-2025-52464
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in duplicated public/private keys. Additionally, the Meshtastic was failing to properly initia... Read more
Affected Products : meshtastic_firmware- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cryptography
-
9.5
CRITICALCVE-2013-10043
A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the logon.php script allows an attacker to bypass authentication via SQL injection. Once authenticated as an administrator, the attacker ca... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Injection
-
9.5
CRITICALCVE-2025-1077
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server conf... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2013-10067
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-34147
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-56320
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, and its associated API. A malicious insider/existing authe... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-34148
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54079
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the endpoint `/html/atendido/Profile_Atendido.php`, in the `idatendido` par... Read more
Affected Products : wegia- Published: Jul. 18, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54058
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-53825
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.4
HIGHCVE-2005-4332
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmw... Read more
Affected Products : network_admission_control_manager_and_server_system_software- EPSS Score: %11.06
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
9.4
HIGHCVE-2007-2170
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE i... Read more
Affected Products : e-business_suite- EPSS Score: %1.89
- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-2439
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.... Read more
- EPSS Score: %1.56
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2007-3192
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.... Read more
Affected Products : just_for_fun_network_management_system- EPSS Score: %2.86
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.4
HIGHCVE-2014-2634
Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.... Read more
Affected Products : service_manager- EPSS Score: %6.59
- Published: Aug. 23, 2014
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-8384
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecifi... Read more
- EPSS Score: %1.06
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character ... Read more
Affected Products : netsweeper- EPSS Score: %8.69
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
9.4
HIGH- EPSS Score: %68.25
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-13625
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.... Read more
Affected Products : ghidra- EPSS Score: %0.32
- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2018-14062
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.... Read more
Affected Products : cospas-sarsat_system- EPSS Score: %0.76
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024