Latest CVE Feed
-
0.0
NONECVE-2025-49831
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-49833
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the webui.py open_slice function. slice_opt_root and slice-inp-path takes user input, which is passed to the o... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-49839
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the ... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
4.5
CVSS30CVE-2025-53842
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerabi... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
8.1
CVSS31CVE-2025-6043
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file() function in all versions up to, and including, 16.8. This make... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
9.8
CVSS31CVE-2025-7673
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitra... Read more
Affected Products : vmg8825-t50k_firmware- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
0.0
NONECVE-2025-40724
Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the u_medicine_name parameter in /edit_medicin... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
6.4
CVSS31CVE-2025-5284
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2 due to... Read more
Affected Products : master_addons- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
2.4
CVSS31CVE-2025-53840
Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
6.5
CVSS31CVE-2025-52080
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
6.5
CVSS31CVE-2025-52081
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the usb_folder parameter.... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
6.5
CVSS31CVE-2025-52082
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
8.8
CVSS31CVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
8.8
CVSS31CVE-2025-7656
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
8.8
CVSS31CVE-2025-7657
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
-
5.4
CVSS31CVE-2025-52377
Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbitrary commands on the device. The vulnerability is present in the web management interface's ping and trac... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
-
5.6
CVSS31CVE-2025-48795
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of s... Read more
Affected Products : cxf- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
-
7.5
CVSS31CVE-2024-42650
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
-
0.0
NONECVE-2025-53893
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.38.0, a Denial of Service (DoS) vulnerability exists in the file processing logic when reading... Read more
Affected Products : filebrowser- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
-
7.1
CVSS31CVE-2025-50819
Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d687) when parsing the the topic.yml file in the generation logic in daily_arxiv.py.... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025