Latest CVE Feed
-
2.7
LOWCVE-2025-48370
auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.69.1, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead... Read more
Affected Products :- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-48057
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked in... Read more
Affected Products : icinga- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
5.7
MEDIUMCVE-2025-46805
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Race Condition
-
5.1
MEDIUMCVE-2025-46803
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
5.6
MEDIUMCVE-2025-23392
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-40651
Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This ... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
2.3
LOWCVE-2025-3864
Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library. Fix for this issue ... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-40673
A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-4963
The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products : wp_extended- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-5082
The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more
Affected Products : wp_attachments- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-4800
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authentica... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-2796
On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under norma... Read more
Affected Products : eos- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-11185
On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.... Read more
Affected Products : eos- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-40911
Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal n... Read more
Affected Products :- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-5279
When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the tok... Read more
Affected Products :- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Cryptography
-
2.9
LOWCVE-2025-48754
In the memory_pages crate 0.1.0 for Rust, division by zero can occur.... Read more
Affected Products :- Published: May. 24, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
2.9
LOWCVE-2025-48755
In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).... Read more
Affected Products :- Published: May. 24, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-24917
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-24916
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not s... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
6.6
MEDIUMCVE-2025-48375
Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP requ... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service