Latest CVE Feed
-
8.1
HIGHCVE-2025-7954
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.... Read more
Affected Products : shopware- Published: Aug. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Race Condition
-
8.8
HIGHCVE-2025-9364
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.... Read more
Affected Products : factorytalk_analytics_logixai- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-28041
Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.... Read more
Affected Products : itranswarp- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
8.3
HIGHCVE-2025-20006
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
7.0
HIGHCVE-2025-20026
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
8.3
HIGHCVE-2025-20032
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.... Read more
Affected Products : proset\/wireless_wifi wi-fi_6_ax201 wi-fi_6_ax101 wi-fi_6_ax203 wi-fi_7_be200 wi-fi_7_be201 wi-fi_7_be202- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-20039
Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Race Condition
-
8.0
HIGHCVE-2025-20046
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
7.0
HIGHCVE-2025-20062
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
8.3
HIGHCVE-2025-20618
Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.... Read more
- Published: May. 13, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-59019
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to disclose information from arbitrary database tables stored within the users' web mounts without having... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-9680
A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting. The attack can be ini... Read more
Affected Products : o2oa- Published: Aug. 30, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-59018
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive i... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-9681
A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting. The attack can be launched remotely. T... Read more
Affected Products : o2oa- Published: Aug. 30, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-59017
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the correspondin... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-59016
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-59015
A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-59014
An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the backend user interface by saving manipulated data in... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-59013
An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-9682
A vulnerability has been found in O2OA up to 10.0-410. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripti... Read more
Affected Products : o2oa- Published: Aug. 30, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting