Latest CVE Feed
-
7.8
HIGHCVE-2023-42131
Ansys SpaceClaim X_B File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim. User interaction is required to exploit this vul... Read more
Affected Products : spaceclaim- Published: May. 03, 2024
- Modified: Aug. 18, 2025
-
7.8
HIGHCVE-2023-44428
MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required to exploit this vulnerabil... Read more
Affected Products : musescore- Published: May. 03, 2024
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2023-44438
Ashlar-Vellum Argon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Argon. User interaction is required to exploit this v... Read more
Affected Products : argon- Published: May. 03, 2024
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2023-44440
Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Lithium. User interaction is required to exploit th... Read more
Affected Products : lithium- Published: May. 03, 2024
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2023-44439
Ashlar-Vellum Xenon Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Xenon. User interaction is required to exploit this v... Read more
Affected Products : xenon- Published: May. 03, 2024
- Modified: Aug. 18, 2025
-
7.5
HIGHCVE-2025-53793
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
7.0
HIGHCVE-2025-53788
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_subsystem_for_linux- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Race Condition
-
8.4
HIGHCVE-2025-53784
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.... Read more
Affected Products : 365_apps office_long_term_servicing_channel office_macos_2024 office_macos_2021 office_2024 office_2021- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2025-53779
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : windows_server_2025- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-53765
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2024-27273
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.... Read more
- Published: May. 07, 2024
- Modified: Aug. 18, 2025
-
6.5
MEDIUMCVE-2025-31513
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-31512
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version eq... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-31511
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-8953
A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. The atta... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-8956
A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-55672
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets e... Read more
Affected Products : superset- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-45314
A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.... Read more
Affected Products : hortusfox- Published: Aug. 13, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-45315
A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.... Read more
Affected Products : hortusfox- Published: Aug. 13, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8986
A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. The at... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection