Latest CVE Feed
-
7.8
HIGHCVE-2023-29336
Win32k Elevation of Privilege Vulnerability... Read more
- Actively Exploited
- Published: May. 09, 2023
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.... Read more
Affected Products : magicinfo_9_server- Actively Exploited
- Published: May. 13, 2025
- Modified: May. 27, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet... Read more
- Published: Sep. 15, 2023
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2022-29799
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-d... Read more
Affected Products : windows_defender_for_endpoint- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2022-23951
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-23950
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-23949
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2021-43310
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-31242
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-31244
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31245
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-31246
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-31247
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An attacker may gain access to protected parts of the file system.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-6884
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and ab... Read more
Affected Products : gutenberg_blocks_with_ai- Published: Aug. 08, 2024
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2022-32174
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.... Read more
Affected Products : gogs- Published: Oct. 11, 2022
- Modified: May. 27, 2025
-
6.2
MEDIUMCVE-2022-31022
Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has us... Read more
Affected Products : bleve- Published: Jun. 01, 2022
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2021-21353
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a ... Read more
- Published: Mar. 03, 2021
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2022-32176
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low ... Read more
Affected Products : gin-vue-admin- Published: Oct. 17, 2022
- Modified: May. 27, 2025
-
4.8
MEDIUMCVE-2024-6158
The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Wi... Read more
- Published: Aug. 12, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-6330
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.... Read more
Affected Products : geo_my_wordpress- Published: Aug. 19, 2024
- Modified: May. 27, 2025