Latest CVE Feed
-
4.8
MEDIUMCVE-2025-4280
MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary c... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-4575
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead mar... Read more
Affected Products : openssl- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-45471
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
4.3
MEDIUM- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-13931
Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.0
HIGHCVE-2024-9639
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-2409
File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: thro... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-2410
Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MA... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
9.0
CRITICALCVE-2025-30171
System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: th... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
8.9
HIGHCVE-2025-30172
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
-
8.2
HIGHCVE-2025-46458
Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan allows SQL Injection. This issue affects occupancyplan: from n/a through 1.0.3.0.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-31049
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2024-7487
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious a... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-3580
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploi... Read more
Affected Products : grafana- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-46488
Missing Authorization vulnerability in dastan800 Visual Builder allows Reflected XSS. This issue affects Visual Builder: from n/a through 1.2.2.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-39490
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler allows PHP Local File Inclusion. This issue affects Backpack Traveler: from n/a through 2.7.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-47631
Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System: from 47.0(20 through 11.... Read more
Affected Products : hospital_management_system- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-48286
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.... Read more
Affected Products : redi_restaurant_reservation- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-47673
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.16.... Read more
Affected Products : arconix_shortcodes- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-47149
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pattern file, infor... Read more
Affected Products : i-filter- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration