Latest CVE Feed
-
7.5
HIGHCVE-2025-53643
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version... Read more
Affected Products : aiohttp- Published: Jul. 14, 2025
- Modified: Aug. 14, 2025
-
5.4
MEDIUMCVE-2025-53925
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authe... Read more
Affected Products : emlog- Published: Jul. 16, 2025
- Modified: Aug. 14, 2025
-
6.1
MEDIUMCVE-2025-53926
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requir... Read more
Affected Products : emlog- Published: Jul. 16, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-6485
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. ... Read more
- Published: Jun. 22, 2025
- Modified: Aug. 14, 2025
-
8.7
HIGHCVE-2025-48387
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a wor... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 14, 2025
-
5.3
MEDIUMCVE-2025-54786
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated ... Read more
Affected Products : suitecrm- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
8.8
HIGHCVE-2025-54788
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can ... Read more
Affected Products : suitecrm- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
6.1
MEDIUMCVE-2024-52680
EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.... Read more
Affected Products : eyoucms- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-50952
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.... Read more
Affected Products : openjpeg- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
3.7
LOWCVE-2024-56339
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.... Read more
Affected Products : websphere_application_server- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
6.6
MEDIUMCVE-2025-44779
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.... Read more
Affected Products : ollama- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
8.7
HIGHCVE-2025-7054
Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/d... Read more
Affected Products : quiche- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-50692
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.... Read more
Affected Products : foxcms- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-48913
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users ... Read more
Affected Products : cxf- Published: Aug. 08, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2023-38264
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deser... Read more
- Published: May. 14, 2024
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2023-43040
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.... Read more
Affected Products : storage_fusion_hci- Published: May. 14, 2024
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2023-51636
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the... Read more
Affected Products : avira_prime- Published: May. 22, 2024
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2023-51637
Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vu... Read more
Affected Products : sante_pacs_server- Published: May. 22, 2024
- Modified: Aug. 14, 2025
-
7.3
HIGHCVE-2024-4454
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the... Read more
Affected Products : windows client_security elements_endpoint_protection email_and_server_security server_security- Published: May. 22, 2024
- Modified: Aug. 14, 2025
-
8.7
HIGHCVE-2024-10383
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporar... Read more
- Published: Feb. 07, 2025
- Modified: Aug. 14, 2025