Latest CVE Feed
-
9.4
CRITICALCVE-2025-6793
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installat... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-6030
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack conf... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cryptography
-
9.4
CRITICALCVE-2025-54782
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a l... Read more
Affected Products : nest- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
9.4
CRITICALCVE-2025-54531
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-54061
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-53825
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-52939
Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.4
CRITICALCVE-2025-52579
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory befor... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cryptography
-
9.4
CRITICALCVE-2025-47788
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server ... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-46816
goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-3476
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-3321
A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.... Read more
Affected Products : onlinesuite_application_package- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-3463
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer t... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
-
9.4
CRITICALCVE-2025-34157
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded J... Read more
Affected Products :- Published: Aug. 27, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-34148
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34151
A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthentica... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34149
A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. E... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-30216
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and pr... Read more
Affected Products : cryptolib- Published: Mar. 25, 2025
- Modified: May. 06, 2025
- Vuln Type: Memory Corruption
-
9.4
CRITICALCVE-2025-30135
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-29757
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization