Latest CVE Feed
-
5.6
MEDIUMCVE-2024-12863
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-32431
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is... Read more
Affected Products : traefik- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-43922
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.... Read more
Affected Products : filewave- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
6.0
MEDIUMCVE-2025-32955
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions r... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-3842
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of the argument fileUpload leads to code injection. The at... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-3846
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file code/http/httprequest.cpp of the component Registration. The manipulation of the argument userna... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-3847
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-3814
The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible ... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUM- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-23176
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more
Affected Products : tcexam- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.6
HIGHCVE-2025-23249
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-32959
CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large fil... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-32960
The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which consists of a file path and name, can be manipulated to return the Content-Type header with text/html if the name part ends with .html. T... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-32961
The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTTP requests. Prior to version 1.1.1, the input parameter, which consists of a file path and name, can be manipulated to return the Conte... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-32963
MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal s... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-43948
Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-42605
This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this vulnerability by manipula... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-42603
This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting API response t... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-42601
This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading t... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-42600
This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brut... Read more
Affected Products :- Published: Apr. 23, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication