Latest CVE Feed
-
7.8
HIGHCVE-2024-27339
Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2024-27340
Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit thi... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2024-27341
Kofax Power PDF PDF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit thi... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2024-27342
Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: Apr. 03, 2024
- Modified: Jun. 03, 2025
-
4.6
MEDIUMCVE-2025-5154
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext s... Read more
Affected Products : phonepe- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-32813
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44892
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.... Read more
- Published: May. 21, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-44895
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.... Read more
- Published: May. 21, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2025-27997
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.... Read more
Affected Products : battle.net- Published: May. 21, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-41339
An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vi... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware vigor2620_firmware +30 more products- Published: Feb. 27, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-44083
An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication... Read more
- Published: May. 21, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-54188
Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root access.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2024-41340
An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware vigor2620_firmware +30 more products- Published: Feb. 27, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2024-41592
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware +38 more products- Published: Oct. 03, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2025-4696
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument searchdata leads to ... Read more
Affected Products : cyber_cafe_management_system- Published: May. 15, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32814
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-32815
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-5149
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid lead... Read more
Affected Products : wcms- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-5150
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperly controlled mod... Read more
Affected Products : docarray- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-5151
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of the file introspect/backend/tools/analysis_tools.py. The manipulation of the argument code leads to code in... Read more
Affected Products : introspect- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection