Latest CVE Feed
-
9.3
CRITICALCVE-2024-25293
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.... Read more
- Published: Mar. 01, 2024
- Modified: May. 13, 2025
-
8.8
HIGHCVE-2023-39311
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. ... Read more
- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-22891
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.... Read more
Affected Products : nteract- Published: Mar. 01, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-26548
An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.... Read more
- Published: Feb. 29, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2024-24035
Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.... Read more
Affected Products : s.i.l.- Published: Mar. 07, 2024
- Modified: May. 13, 2025
-
8.8
HIGHCVE-2024-23510
Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1.8. ... Read more
Affected Products : dont_muck_my_markup- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2020-36845
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.... Read more
Affected Products : security_awareness_training- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2020-36844
The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.... Read more
Affected Products : security_awareness_training- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-43955
TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.... Read more
Affected Products : convertigo- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-25997
Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 13, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-39722
An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/push route.... Read more
Affected Products : ollama- Published: Oct. 31, 2024
- Modified: May. 13, 2025
-
8.1
HIGHCVE-2024-26469
Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in ... Read more
Affected Products : product_designer- Published: Mar. 03, 2024
- Modified: May. 13, 2025
-
4.9
MEDIUMCVE-2025-2487
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MOD... Read more
- Published: Mar. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2022-3540
An issue has been discovered in hunter2 affecting all versions before 2.1.0. Improper handling of auto-completion input allows an authenticated attacker to extract other users email addresses... Read more
Affected Products : hunter2- EPSS Score: %0.04
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2022-3517
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.... Read more
- EPSS Score: %0.46
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2023-52555
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.... Read more
Affected Products : mongo-express- Published: Mar. 01, 2024
- Modified: May. 13, 2025
-
6.8
MEDIUMCVE-2024-38888
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2024-38885
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: May. 13, 2025
-
7.8
HIGHCVE-2024-38884
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication ... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: May. 13, 2025
-
9.1
CRITICALCVE-2024-38883
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: May. 13, 2025