Latest CVE Feed
-
8.5
HIGHCVE-2025-48479
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue has ... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Path Traversal
-
7.0
HIGHCVE-2025-48480
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htaccess dur... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-48481
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked or del... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-48482
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, the f... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-48483
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sanitiz... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-48484
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST data... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.... Read more
Affected Products : coffee- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2679
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact-us.php. The manipulation of the argument pagetitle leads to sql injection. It is possible t... Read more
- Published: Mar. 24, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-13246
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.... Read more
Affected Products : node_access_rebuild_progressive- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-2680
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edit-assign-locker.php?ltid=1. The manipulation of the argument mobilenumb... Read more
- Published: Mar. 24, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-23899
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to ... Read more
Affected Products : git_server- Published: Jan. 24, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2022-25708
Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile... Read more
Affected Products : sd_8_gen1_5g_firmware sd888_5g_firmware wcd9380_firmware wcd9385_firmware wcn6850_firmware wcn6851_firmware wcn6855_firmware wcn6856_firmware wcn7850_firmware wcn7851_firmware +24 more products- Published: Sep. 16, 2022
- Modified: Jun. 04, 2025
-
6.5
MEDIUMCVE-2020-36603
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows system... Read more
Affected Products : mhyprot2- Published: Sep. 14, 2022
- Modified: Jun. 04, 2025
-
8.8
HIGHCVE-2024-13260
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.... Read more
Affected Products : migrate_queue_importer- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2024-13259
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.... Read more
Affected Products : image_sizes- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-13258
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.... Read more
Affected Products : rest_\&_json_api_authentication- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13257
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.... Read more
Affected Products : commerce_view_receipt- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13256
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.... Read more
Affected Products : email_contact- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-31679
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Ignition Error Pages allows Cross-Site Scripting (XSS).This issue affects Ignition Error Pages: from 0.0.0 before 1.0.4.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.2
HIGHCVE-2025-31678
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization