Latest CVE Feed
-
8.8
HIGHCVE-2025-2847
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. Th... Read more
Affected Products : gym_management_system- Published: Mar. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-2151
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buff... Read more
Affected Products : assimp- Published: Mar. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2025-3395
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.... Read more
Affected Products : automation_builder- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-3394
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.... Read more
Affected Products : automation_builder- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2024-51319
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-5186
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the ar... Read more
Affected Products : jeesite- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Server-Side Request Forgery
-
9.2
CRITICALCVE-2025-5124
A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of defa... Read more
Affected Products :- Published: May. 24, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-37265
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.... Read more
Affected Products : steal- EPSS Score: %0.14
- Published: Sep. 20, 2022
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-25734
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.... Read more
- Published: Mar. 27, 2024
- Modified: May. 28, 2025
-
9.1
CRITICALCVE-2024-25735
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.... Read more
- Published: Mar. 27, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-25736
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.... Read more
- Published: Mar. 27, 2024
- Modified: May. 28, 2025
-
7.8
HIGHCVE-2025-2308
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads to heap-based buffer overflow. An attack has to be app... Read more
Affected Products : hdf5- Published: Mar. 14, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2309
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is required to appro... Read more
Affected Products : hdf5- Published: Mar. 14, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2310
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The ex... Read more
Affected Products : hdf5- Published: Mar. 14, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.0
HIGHCVE-2024-25423
An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.... Read more
Affected Products : cinema_4d- Published: Feb. 22, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2023-31634
In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations.... Read more
- Published: Mar. 27, 2024
- Modified: May. 28, 2025
-
6.5
MEDIUMCVE-2025-25225
A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to escalate their privileges to Super Admin Permissions.... Read more
Affected Products : hikashop- Published: Mar. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-3479
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user contro... Read more
- Published: Apr. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-48419
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of the... Read more
- Published: Jan. 27, 2025
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2024-48416
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.... Read more
- Published: Jan. 27, 2025
- Modified: May. 28, 2025