Latest CVE Feed
-
5.5
MEDIUMCVE-2025-30305
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue re... Read more
Affected Products : xmp_toolkit_software_development_kit- Published: Apr. 08, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-43014
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation... Read more
Affected Products : toolbox- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2024-40507
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 26, 2024
- Modified: Apr. 23, 2025
-
7.3
HIGHCVE-2024-40508
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 26, 2024
- Modified: Apr. 23, 2025
-
7.3
HIGHCVE-2024-40511
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 27, 2024
- Modified: Apr. 23, 2025
-
7.3
HIGHCVE-2024-40512
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 27, 2024
- Modified: Apr. 23, 2025
-
7.3
HIGHCVE-2024-40506
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.... Read more
Affected Products : openpetra- Published: Sep. 26, 2024
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2025-3679
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exp... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-3163
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the ... Read more
Affected Products : lmdeploy- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-43013
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible... Read more
Affected Products : toolbox- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-42921
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin... Read more
Affected Products : toolbox- Published: Apr. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3164
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Han... Read more
Affected Products : supersonic- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2022-46792
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)... Read more
Affected Products : graphql_engine- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
4.3
MEDIUMCVE-2022-46685
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.... Read more
Affected Products : gitea- Published: Dec. 12, 2022
- Modified: Apr. 23, 2025
-
6.5
MEDIUMCVE-2022-45667
Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2022-45548
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.... Read more
Affected Products : ayacms- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-45525
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-45524
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-45523
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-45522
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025