Latest CVE Feed
-
8.5
HIGHCVE-2025-43596
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (re... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
9.2
CRITICALCVE-2025-34026
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to h... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
6.7
MEDIUMCVE-2025-30173
File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
5.9
MEDIUMCVE-2025-30170
Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: ... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-2272
Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, Hijacking a privileged process.This issue affects FIE Endpoint: before 25.05.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-23183
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2024-9544
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w... Read more
Affected Products : mapsvg- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-48850
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
9.5
CRITICALCVE-2024-48853
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
-
7.5
HIGHCVE-2024-13929
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2024-13930
An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MA... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Denial of Service
-
8.6
HIGHCVE-2025-34025
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to t... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-4280
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary c... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-4575
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead mar... Read more
Affected Products : openssl- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-45471
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUM- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-13931
Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.0
HIGHCVE-2024-9639
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-2409
File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: thro... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-2410
Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MA... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration