Latest CVE Feed
-
3.3
LOWCVE-2025-23340
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of serv... Read more
- Published: Sep. 24, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Denial of Service
-
3.3
LOWCVE-2025-23346
NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to a limited denial of service.... Read more
- Published: Sep. 24, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-0209
A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding. A malicious actor can exploit this vulnerability by injecting a crafted payload that is reflected in the ... Read more
Affected Products : identity_server- Published: Sep. 23, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-0663
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user ... Read more
- Published: Sep. 23, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-1396
A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username se... Read more
- Published: Sep. 26, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-1862
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user... Read more
Affected Products : api_manager identity_server identity_server_as_key_manager enterprise_integrator open_banking_iam- Published: Sep. 26, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-6429
A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content ... Read more
- Published: Sep. 23, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-4598
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is no... Read more
- Published: Sep. 23, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-3193
Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extrem... Read more
Affected Products : algoliasearch-helper- Published: Sep. 27, 2025
- Modified: Oct. 05, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-57971
Missing Authorization vulnerability in SALESmanago SALESmanago & Leadoo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SALESmanago & Leadoo: from n/a through 3.8.1.... Read more
Affected Products : salesmanago- Published: Sep. 22, 2025
- Modified: Oct. 04, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-57970
Cross-Site Request Forgery (CSRF) vulnerability in SALESmanago SALESmanago & Leadoo allows Cross Site Request Forgery.This issue affects SALESmanago & Leadoo: from n/a through 3.8.1.... Read more
Affected Products : salesmanago- Published: Sep. 22, 2025
- Modified: Oct. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-10989
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack can ... Read more
Affected Products : ruoyi- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-10993
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the component Template Management. The manipulation results in code injection. It is possible to launch the attack rem... Read more
Affected Products : muyucms- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
-
4.0
MEDIUMCVE-2025-10859
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143... Read more
Affected Products : firefox- Published: Sep. 30, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-11152
This vulnerability affects Firefox < 143.0.3.... Read more
Affected Products : firefox- Published: Sep. 30, 2025
- Modified: Oct. 03, 2025
-
8.8
HIGHCVE-2025-55848
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection commands.... Read more
- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-45994
An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.... Read more
Affected Products : passrecovery- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-55847
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute ar... Read more
- Published: Sep. 26, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-56379
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-36144
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.... Read more
Affected Products : watsonx.data- Published: Sep. 27, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Information Disclosure