Latest CVE Feed
-
8.8
HIGHCVE-2025-5150
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperly controlled mod... Read more
Affected Products : docarray- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-5151
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of the file introspect/backend/tools/analysis_tools.py. The manipulation of the argument code leads to code in... Read more
Affected Products : introspect- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5152
A vulnerability classified as critical was found in Chanjet CRM up to 20250510. This vulnerability affects unknown code of the file /activity/newActivityedit.php?DontCheckLogin=1&id=null&ret=mod1. The manipulation of the argument gblOrgID leads to sql inj... Read more
Affected Products : chanjet_cms- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-5153
A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design Manager Module. The manipulation of the argument Description leads to cross site scripting. ... Read more
Affected Products : cms_made_simple- Published: May. 25, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-46256
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.... Read more
- Published: Sep. 27, 2024
- Modified: Jun. 03, 2025
-
6.3
MEDIUMCVE-2024-46257
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.... Read more
- Published: Sep. 27, 2024
- Modified: Jun. 03, 2025
-
8.0
HIGHCVE-2023-49528
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.... Read more
- Published: Apr. 12, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2024-6119
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal terminati... Read more
Affected Products : active_iq_unified_manager h410c_firmware ontap_select_deploy_administration_utility openssl h300s_firmware h500s_firmware h700s_firmware h410s_firmware a250_firmware 500f_firmware +21 more products- Published: Sep. 03, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-0579
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command inject... Read more
- EPSS Score: %1.02
- Published: Jan. 16, 2024
- Modified: Jun. 03, 2025
-
7.1
HIGHCVE-2023-4387
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up... Read more
- EPSS Score: %0.02
- Published: Aug. 16, 2023
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2023-48863
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some at... Read more
Affected Products : semcms- EPSS Score: %0.24
- Published: Dec. 04, 2023
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-48842
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.... Read more
- EPSS Score: %19.39
- Published: Dec. 01, 2023
- Modified: Jun. 03, 2025
-
7.8
HIGHCVE-2023-48645
An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search wo... Read more
Affected Products : archibus- EPSS Score: %0.03
- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
5.4
MEDIUMCVE-2024-23782
Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.... Read more
Affected Products : a-blog_cms- EPSS Score: %0.38
- Published: Jan. 28, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-51842
An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.... Read more
Affected Products : meshcentral- EPSS Score: %0.19
- Published: Jan. 29, 2024
- Modified: Jun. 02, 2025
-
7.2
HIGHCVE-2023-49038
Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.... Read more
- EPSS Score: %1.03
- Published: Jan. 29, 2024
- Modified: Jun. 02, 2025
-
4.8
MEDIUMCVE-2025-31682
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Google Tag allows Cross-Site Scripting (XSS).This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-31683
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Google Tag allows Cross Site Request Forgery.This issue affects Google Tag: from 0.0.0 before 1.8.0, from 2.0.0 before 2.0.8.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.8
MEDIUMCVE-2025-31680
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-25090
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dreamstime Dreamstime Stock Photos dreamstime-stock-photos allows Reflected XSS.This issue affects Dreamstime Stock Photos: from n/a through 4.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting