Latest CVE Feed
-
8.8
HIGHCVE-2025-33137
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-33138
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-52874
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2025-48066
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletio... Read more
Affected Products : wire-webapp- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-48075
Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber.Ctx.BodyParser` can map flat data to nested slices using `key[idx]value` syntax, but when idx is negative, it causes a panic instead o... Read more
Affected Products : fiber- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-48366
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a stored and blind XSS vulnerability exists in the Phone Number field of the user profile within the GroupOffice application. This al... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.8
MEDIUMCVE-2025-48368
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a DOM-based Cross-Site Scripting (XSS) vulnerability exists in the GroupOffice application, allowing attackers to execute arbitrary J... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-48369
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20, a persistent Cross-Site Scripting (XSS) vulnerability exists in Groupoffice's tasks comment functionality, allowing attackers to exec... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2024-40458
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-40459
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-40460
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-40461
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-40462
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-41195
An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-41196
An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-41197
An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-41198
An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-41199
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.... Read more
Affected Products : innovation- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2021-29505
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. ... Read more
- EPSS Score: %90.77
- Published: May. 28, 2021
- Modified: May. 30, 2025
-
7.5
HIGHCVE-2021-21265
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly configured servers (i.e. the server routes any request, regardless of the HOST header to an October CMS in... Read more
Affected Products : october- EPSS Score: %0.47
- Published: Mar. 10, 2021
- Modified: May. 30, 2025