Latest CVE Feed
-
7.5
HIGHCVE-2022-2721
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.... Read more
Affected Products : octopus_server- Published: Nov. 25, 2022
- Modified: Apr. 25, 2025
-
8.8
HIGHCVE-2022-23044
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF. ... Read more
Affected Products : tiny_file_manager- Published: Nov. 25, 2022
- Modified: Apr. 25, 2025
-
6.1
MEDIUMCVE-2022-0698
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.... Read more
- Published: Nov. 25, 2022
- Modified: Apr. 25, 2025
-
9.1
CRITICALCVE-2024-1735
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.... Read more
Affected Products : armeria- Published: Feb. 26, 2024
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-49960
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.... Read more
- Published: Feb. 26, 2024
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-43326
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.... Read more
- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-42109
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.... Read more
Affected Products : online-shopping-system-advanced- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-42100
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.... Read more
Affected Products : klik- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-2766
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The ... Read more
- Published: May. 17, 2023
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-2765
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The att... Read more
- Published: May. 17, 2023
- Modified: Apr. 25, 2025
-
7.3
HIGHCVE-2023-42875
Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.... Read more
- Published: Apr. 11, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2023-38614
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.... Read more
- Published: Apr. 11, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28399
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.... Read more
Affected Products : xmall- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2023-37187
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.... Read more
- Published: Dec. 25, 2023
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-37188
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.... Read more
- Published: Dec. 25, 2023
- Modified: Apr. 25, 2025
-
9.3
HIGHCVE-2020-29367
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.... Read more
- Published: Nov. 27, 2020
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-37185
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c.... Read more
- Published: Dec. 25, 2023
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2023-37186
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset.... Read more
- Published: Dec. 25, 2023
- Modified: Apr. 25, 2025
-
5.5
MEDIUMCVE-2025-29213
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.... Read more
Affected Products : jeewms- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Path Traversal
-
5.9
MEDIUMCVE-2024-44843
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.... Read more
Affected Products : steve- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authentication