Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 0.0

    NONE
    CVE-2024-42646

    A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-53643

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2024-42649

    NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-53823

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerability in the endpoint `/WeGIA/html/socio/sistema/processa_deletar_socio.php`, in the `id_socio` p... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2024-42648

    NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2024-51770

    An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-7618

    A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to inject malicious scripts into the applications, which may then access cookies or other s... Read more

    Affected Products : data_master
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-50756

    Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-53640

    Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2024-26293

    The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEX... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2024-26292

    An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-53639

    MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply crafted input to inject and execute arbitrary SQL statem... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
  • 0.0

    NONE
    CVE-2025-53623

    The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code execution vulnerability in the `CsvEnumerator` class. This vulnerability can be exploited by an attacker to e... Read more

    Affected Products :
    • Published: Jul. 14, 2025
    • Modified: Jul. 14, 2025
Showing 20 of 173 Results
© cvefeed.io
Latest DB Update: Jul. 15, 2025 6:28