Latest CVE Feed
-
7.5
HIGHCVE-2025-8800
A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme/esm-handler.c of the component AMF Component. The manipulation leads to denial of service. The attack may... Read more
Affected Products : open5gs- Published: Aug. 10, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-8452
By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described b... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2021-27923
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.... Read more
- EPSS Score: %0.60
- Published: Mar. 03, 2021
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2021-27922
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.... Read more
- EPSS Score: %0.35
- Published: Mar. 03, 2021
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2021-27921
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.... Read more
- EPSS Score: %0.60
- Published: Mar. 03, 2021
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2025-21756
In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during conne... Read more
Affected Products : linux_kernel- Published: Feb. 27, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2021-20087
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.... Read more
Affected Products : jquery-deparam- EPSS Score: %1.79
- Published: Apr. 23, 2021
- Modified: Aug. 14, 2025
-
4.7
MEDIUMCVE-2020-9295
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR arch... Read more
- Published: Mar. 17, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-54951
Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.... Read more
Affected Products : monica- Published: Feb. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-57329
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.... Read more
Affected Products : hortusfox- Published: Jan. 23, 2025
- Modified: Aug. 14, 2025
-
5.3
MEDIUMCVE-2025-36034
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.... Read more
Affected Products : infosphere_information_server- Published: Jun. 26, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2025-49321
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin allows Reflected XSS. This issue affects Eventin: from n/a through 4.0.28.... Read more
Affected Products : eventin- Published: Jun. 27, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-36582
Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to I... Read more
Affected Products : networker- Published: Jul. 01, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-45872
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.... Read more
Affected Products : zrlog- Published: Jul. 01, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Server-Side Request Forgery
-
9.1
CRITICALCVE-2025-53632
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of the file to write is not checked, potentially leading to zip slips. Exploitation does not require authen... Read more
Affected Products : chall-manager- Published: Jul. 10, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-53633
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially leading to zip bombs decompression. Exploitation does no... Read more
Affected Products : chall-manager- Published: Jul. 10, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2025-53634
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, an attacker could cause Denial of Service (DoS). Exploitation does not requi... Read more
Affected Products : chall-manager- Published: Jul. 10, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-53643
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version... Read more
Affected Products : aiohttp- Published: Jul. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-53925
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows authenticated remote attackers to inject arbitrary web script or HTML via the file upload functionality. As an authe... Read more
Affected Products : emlog- Published: Jul. 16, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-53926
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the comment and comname parameters. Reflected XSS requir... Read more
Affected Products : emlog- Published: Jul. 16, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting