Latest CVE Feed
-
7.8
HIGHCVE-2025-30325
Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in ... Read more
- Published: May. 13, 2025
- Modified: May. 22, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-4544
A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of the component jhttpd. The manipulation of the argument def_max/def_time/def_tcp_max/def_tcp_time/d... Read more
- Published: May. 11, 2025
- Modified: May. 22, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-4858
A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been declared as problematic. This vulnerability affects unknown code of the file /adv_arpspoofing.php of the component ARP Spoofing Prevention Page. The manipulation of the a... Read more
- Published: May. 18, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-4859
A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue affects some unknown processing of the file /adv_macbypass.php of the component MAC Bypass Settings Page. The manipulation of the argumen... Read more
- Published: May. 18, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-0810
Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2024-0804
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 24, 2024
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2024-0755
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera... Read more
- Published: Jan. 23, 2024
- Modified: May. 22, 2025
-
6.5
MEDIUMCVE-2024-0754
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.... Read more
Affected Products : firefox- Published: Jan. 23, 2024
- Modified: May. 22, 2025
-
4.3
MEDIUMCVE-2024-0749
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.... Read more
- Published: Jan. 23, 2024
- Modified: May. 22, 2025
-
6.5
MEDIUMCVE-2024-0747
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.... Read more
- Published: Jan. 23, 2024
- Modified: May. 22, 2025
-
8.8
HIGHCVE-2024-0517
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 16, 2024
- Modified: May. 22, 2025
-
6.1
MEDIUMCVE-2024-0187
The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users... Read more
Affected Products : peepso- Published: Jan. 16, 2024
- Modified: May. 22, 2025
-
4.8
MEDIUMCVE-2023-5124
The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site Wor... Read more
Affected Products : pagelayer- Published: Jan. 29, 2024
- Modified: May. 22, 2025
-
7.0
HIGHCVE-2023-5091
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.... Read more
Affected Products : valhall_gpu_kernel_driver- Published: Jan. 08, 2024
- Modified: May. 22, 2025
-
9.8
CRITICALCVE-2023-48085
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.... Read more
Affected Products : nagios_xi- Published: Dec. 14, 2023
- Modified: May. 22, 2025
-
6.1
MEDIUMCVE-2023-46750
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+. ... Read more
Affected Products : shiro- Published: Dec. 14, 2023
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2023-41151
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.... Read more
- Published: Dec. 14, 2023
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-40103
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2022-40102
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
7.5
HIGHCVE-2022-40101
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025