Latest CVE Feed
-
9.8
CRITICALCVE-2012-10023
A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The fla... Read more
Affected Products : freefloat_ftp_server- Published: Aug. 05, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2012-10030
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, an... Read more
Affected Products : freefloat_ftp_server- Published: Aug. 05, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-55564
Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.... Read more
- Published: Aug. 21, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-25007
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-25006
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-53783
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-33051
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-55613
Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.... Read more
- Published: Aug. 22, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-8191
A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site ... Read more
Affected Products : mall- Published: Jul. 26, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8343
A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the ... Read more
Affected Products : shio- Published: Jul. 31, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-27286
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one message, ... Read more
- Published: Mar. 20, 2024
- Modified: Sep. 03, 2025
-
8.8
HIGHCVE-2020-24363
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrati... Read more
- Actively Exploited
- EPSS Score: %34.58
- Published: Aug. 31, 2020
- Modified: Sep. 03, 2025
-
9.8
CRITICALCVE-2025-8344
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument file... Read more
Affected Products : shio- Published: Jul. 31, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-9822
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credential... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-47421
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted S... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-37744
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_pci_remove() Kmemleak reported this error: unreferenced object 0xffff1c165cec3060 (size 32): comm "insmod", pid 560, jiffies 4296964570 (a... Read more
Affected Products : linux_kernel- Published: May. 01, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
8.6
HIGHCVE-2025-2416
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass.This issue affects LimonDesk: from s1.02.14 before v1.02.17.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-26210
An Cross-Site Scripting (XSS) vulnerability in DeepSeek R1 through V3.1 allows a remote attacker to execute arbitrary code via unspecified input fields.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-0878
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).This issue affects LimonDesk: from s1.02.14 before v1.02.17.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-13068
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue affects LimonDesk: from s1.02.14 before v1.02.17.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization