Latest CVE Feed
-
4.4
MEDIUMCVE-2025-29768
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filen... Read more
- Published: Mar. 13, 2025
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2025-2449
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vu... Read more
Affected Products : flexlogger- Published: Mar. 18, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-2450
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit ... Read more
Affected Products : vision_builder_ai- Published: Mar. 18, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2023-38272
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.... Read more
Affected Products : cloud_pak_system- Published: Mar. 27, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
4.4
MEDIUMCVE-2025-29989
Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.... Read more
- Published: Apr. 10, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2023-6377
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases wh... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_eus x_server libssh tigervnc xwayland- EPSS Score: %0.36
- Published: Dec. 13, 2023
- Modified: Aug. 18, 2025
-
4.1
MEDIUMCVE-2025-45582
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an ... Read more
Affected Products : tar- Published: Jul. 11, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-8671
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening... Read more
Affected Products : h2o- Published: Aug. 13, 2025
- Modified: Aug. 17, 2025
- Vuln Type: Denial of Service
-
7.0
HIGHCVE-2025-45770
jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and othe... Read more
Affected Products : jwt- Published: Jul. 31, 2025
- Modified: Aug. 17, 2025
- Vuln Type: Cryptography
-
7.3
HIGHCVE-2025-45769
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and... Read more
Affected Products : firebase_php-jwt- Published: Jul. 31, 2025
- Modified: Aug. 17, 2025
- Vuln Type: Cryptography
-
7.0
HIGHCVE-2025-45766
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14... Read more
Affected Products : poco- Published: Aug. 06, 2025
- Modified: Aug. 17, 2025
- Vuln Type: Cryptography
-
10.0
CRITICALCVE-2023-43029
IBM Storage Virtualize vSphere Remote Plug-in 1.0 and 1.1 could allow a remote user to obtain sensitive credential information after deployment.... Read more
- Published: Mar. 21, 2025
- Modified: Aug. 17, 2025
- Vuln Type: Information Disclosure
-
9.0
CRITICALCVE-2025-23266
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalati... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Aug. 16, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-8885
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bcprov, bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files https://git... Read more
Affected Products : bouncy_castle_for_java- Published: Aug. 12, 2025
- Modified: Aug. 16, 2025
- Vuln Type: Denial of Service
-
10.0
CRITICALCVE-2025-20265
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerabilit... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8936
A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may ... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8935
A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be lau... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-8934
A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file /sales.php. The manipulation of the argument select2112 leads to cross site scripting. It is possible to launch the attack remotely. T... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-8933
A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to cross site scripting. The attack may be in... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-8920
A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of the file /dicionario-de-termos-bncc of the component Dicionário de Termos BNCC Page. The manipulation of the argument Planos de ensino... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting