Latest CVE Feed
-
4.9
MEDIUMCVE-2025-46344
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not... Read more
Affected Products : nextjs-auth0- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
8.6
HIGHCVE-2025-29906
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authenticati... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
6.3
MEDIUMCVE-2025-46552
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord ... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.0
MEDIUMCVE-2025-24339
A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the vulnerable system, including web cache poisoning or Man-in-the-Middle (MitM), via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-24341
A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoS) condition on the device via multiple crafted HTTP requests. In the worst case, a full power cycle is needed to r... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.4
MEDIUMCVE-2025-24343
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.3
MEDIUMCVE-2025-24345
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the “hosts” file in an unintended manner via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-24347
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
7.1
HIGHCVE-2025-24350
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary certificates in arbitrary file system paths via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-27532
A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to access secret information via multiple crafted HTTP requests.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
8.5
HIGHCVE-2024-9876
: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.8
MEDIUMCVE-2025-46331
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certa... Read more
Affected Products : openfga- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
4.6
MEDIUMCVE-2022-42449
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2023-45721
Insufficient default configuration in HCL Leap allows anonymous access to directory information.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-2890
The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ parameter in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient ... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2025-24342
A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
2.6
LOWCVE-2024-47784
Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
8.2
HIGHCVE-2025-32777
Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2025-46554
XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
8.4
HIGHCVE-2025-46557
XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can acces... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 02, 2025