Latest CVE Feed
-
6.5
MEDIUMCVE-2025-33004
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.... Read more
Affected Products : planning_analytics_local- Published: Jun. 01, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-33005
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.... Read more
Affected Products : planning_analytics_local- Published: Jun. 01, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2025-46154
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.... Read more
Affected Products : foxcms- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-43923
An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.... Read more
Affected Products : focal_point- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-43924
Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an ... Read more
Affected Products : focal_point- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-44148
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component... Read more
Affected Products : mailenable- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.... Read more
Affected Products : foxcms- Published: Mar. 27, 2025
- Modified: Jun. 09, 2025
-
8.8
HIGHCVE-2024-25251
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.... Read more
- Published: Feb. 22, 2024
- Modified: Jun. 09, 2025
-
7.8
HIGHCVE-2024-21116
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where... Read more
- Published: Apr. 16, 2024
- Modified: Jun. 09, 2025
-
8.6
HIGHCVE-2024-21136
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated att... Read more
Affected Products : retail_xstore_office- Published: Jul. 16, 2024
- Modified: Jun. 09, 2025
-
7.1
HIGHCVE-2024-21026
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with netw... Read more
Affected Products : complex_maintenance_repair_and_overhaul- Published: Apr. 16, 2024
- Modified: Jun. 09, 2025
-
9.1
CRITICALCVE-2024-21175
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access v... Read more
Affected Products : weblogic_server- Published: Jul. 16, 2024
- Modified: Jun. 09, 2025
-
6.5
MEDIUMCVE-2023-5388
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.... Read more
- Published: Mar. 19, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-12976
A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /staff.php. The manipulation of the argument tel leads to sql injection. The att... Read more
Affected Products : hospital_management_system hospital_management_system hospital_management_system- Published: Dec. 27, 2024
- Modified: Jun. 09, 2025
-
5.5
MEDIUMCVE-2024-53901
The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image.... Read more
- Published: Nov. 24, 2024
- Modified: Jun. 09, 2025
-
7.5
HIGHCVE-2025-2917
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation of the argument filePath leads to path traversal. It is possible to launch t... Read more
- Published: Mar. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-24304
In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.... Read more
Affected Products : mailjet- Published: Feb. 07, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-24188
Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.... Read more
Affected Products : jsish- Published: Feb. 07, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-24021
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.... Read more
Affected Products : novel-plus- Published: Feb. 08, 2024
- Modified: Jun. 09, 2025
-
5.6
MEDIUMCVE-2024-11616
Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and t... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jun. 09, 2025