Latest CVE Feed
- 
                                
                                
8.4
HIGHCVE-2025-61859
An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execut... Read more
Affected Products : monitouch_v-sft- Published: Oct. 10, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
8.4
HIGHCVE-2025-61857
An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code... Read more
Affected Products : monitouch_v-sft- Published: Oct. 10, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
8.4
HIGHCVE-2025-61856
A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary co... Read more
Affected Products : monitouch_v-sft- Published: Oct. 10, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
8.4
HIGHCVE-2025-11957
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and ent... Read more
Affected Products : devolutions_server- Published: Oct. 22, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
8.4
HIGHCVE-2025-23356
NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.... Read more
Affected Products :- Published: Oct. 14, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.4
HIGHCVE-2025-11192
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense imple... Read more
Affected Products :- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
8.4
HIGHCVE-2025-8432
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 befo... Read more
Affected Products : infra_monitoring- Published: Oct. 27, 2025
 - Modified: Oct. 30, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.4
HIGHCVE-2025-12509
On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.... Read more
Affected Products : brain2- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
8.4
HIGHCVE-2025-61865
NarSuS App registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.... Read more
Affected Products :- Published: Oct. 23, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.4
HIGHCVE-2025-53049
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high pr... Read more
Affected Products : business_intelligence- Published: Oct. 21, 2025
 - Modified: Oct. 23, 2025
 
 - 
                                
                                
8.4
HIGHCVE-2025-12508
When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.... Read more
Affected Products : brain2- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cryptography
 
 - 
                                
                                
8.4
HIGHCVE-2025-58299
Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Oct. 11, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
8.4
HIGHCVE-2025-0636
EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.... Read more
Affected Products :- Published: Oct. 13, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
8.4
HIGHCVE-2025-57781
The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.... Read more
Affected Products :- Published: Oct. 06, 2025
 - Modified: Oct. 06, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.4
HIGHCVE-2025-53782
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.... Read more
- Published: Oct. 14, 2025
 - Modified: Oct. 27, 2025
 
 - 
                                
                                
8.4
HIGHCVE-2025-61863
An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.... Read more
Affected Products : monitouch_v-sft- Published: Oct. 10, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
8.4
HIGHCVE-2025-34287
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could mo... Read more
Affected Products : xi- Published: Oct. 30, 2025
 - Modified: Oct. 30, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
8.4
HIGHCVE-2025-61864
A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.... Read more
Affected Products : monitouch_v-sft- Published: Oct. 10, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
8.4
HIGHCVE-2025-43281
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.... Read more
Affected Products : macos- Published: Oct. 15, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
8.4
HIGHCVE-2025-62776
The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.... Read more
Affected Products :- Published: Oct. 29, 2025
 - Modified: Oct. 30, 2025
 - Vuln Type: Misconfiguration