Latest CVE Feed
-
8.8
HIGHCVE-2025-3585
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate ... Read more
Affected Products : cicadascms- Published: Apr. 14, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2024-51010
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute... Read more
Affected Products : r7000p_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: May. 21, 2025
-
7.2
HIGHCVE-2025-3565
A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation of the argument ... Read more
- Published: Apr. 14, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
3.7
LOWCVE-2024-21011
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracl... Read more
Affected Products : debian_linux active_iq_unified_manager oncommand_insight oncommand_workflow_automation jdk jre graalvm java_se graalvm_for_jdk data_infrastructure_insights_acquisition_unit +1 more products- Published: Apr. 16, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2025-3608
A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.... Read more
Affected Products : firefox- Published: Apr. 15, 2025
- Modified: May. 21, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-20955
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-20957
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
-
4.4
MEDIUMCVE-2025-20958
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-20959
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2025-20960
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20961
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2025-20962
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-20963
Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-20964
Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.... Read more
Affected Products : android- Published: May. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-44848
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44860
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44861
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44862
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44863
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
3.7
LOWCVE-2024-21094
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracl... Read more
Affected Products : debian_linux active_iq_unified_manager oncommand_insight oncommand_workflow_automation jdk jre graalvm java_se graalvm_for_jdk data_infrastructure_insights_acquisition_unit +1 more products- Published: Apr. 16, 2024
- Modified: May. 21, 2025