Latest CVE Feed
-
9.4
CRITICALCVE-2025-3114
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise. Sandbox Bypass Vulnerability: A flaw in the TERR security... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.4
CRITICALCVE-2025-36852
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storage, or similar object storage) that allows any contributor with pull request... Read more
Affected Products : nx-remotecache-azure nx-remotecache-custom azure-cache gcs-cache s3-cache shared-fs-cache nx-remotecache-minio- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Supply Chain
-
9.4
CRITICALCVE-2025-48047
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.... Read more
Affected Products :- Published: May. 29, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-49008
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary command execution. Atheo... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2024-48849
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.... Read more
Affected Products :- Published: Jan. 29, 2025
- Modified: Jan. 29, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-22140
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitr... Read more
Affected Products : wegia- Published: Jan. 08, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-22141
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands,... Read more
Affected Products : wegia- Published: Jan. 08, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-22152
Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities c... Read more
Affected Products :- Published: Jan. 10, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2024-42168
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content.... Read more
Affected Products : dryice_myxalytics- Published: Jan. 11, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
9.4
CRITICALCVE-2025-1980
The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, as it was by default when installed at the turn of 2021 and 2022, it can result in Remote Code Execution. ... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
9.4
CRITICALCVE-2025-6029
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is ... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cryptography
-
9.4
CRITICALCVE-2025-49596
The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requ... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-53695
OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.... Read more
Affected Products : istar_ultra_firmware- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-54298
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-54299
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2019-19108
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-53120
A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server.... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-25182
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with A... Read more
Affected Products : stroom- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2019-17638
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ... Read more
Affected Products : jetty- Published: Jul. 09, 2020
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2007-2386
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.... Read more
- Published: May. 24, 2007
- Modified: Apr. 09, 2025