Latest CVE Feed
-
7.0
HIGHCVE-2025-27703
CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permiss... Read more
Affected Products : secure_access- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
4.6
MEDIUMCVE-2025-27706
CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere with another system administrator’s use of the management c... Read more
Affected Products : secure_access- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-46078
HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server... Read more
Affected Products : huocms- Published: May. 29, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-46080
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.... Read more
Affected Products : huocms- Published: May. 29, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-41385
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user.... Read more
- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-41406
Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be executed on the web browser of the moderator user.... Read more
- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-47697
Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated attacker may bypass authentication and operate the affected device as the moderator user.... Read more
- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-48486
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and __, allowing user input to be exec... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.0
MEDIUMCVE-2025-48487
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-48488
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripting (X... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-48489
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been pat... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48492
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote... Read more
Affected Products : getsimple_cms- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-48865
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds ... Read more
Affected Products : fabio- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-48875
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3936
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Niagara... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-3937
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-3938
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2025-3939
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before ... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-3940
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before ... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3941
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.1... Read more
- Published: May. 22, 2025
- Modified: Jun. 04, 2025