Latest CVE Feed
-
6.8
MEDIUMCVE-2021-35567
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitabl... Read more
Affected Products : fedora debian_linux active_iq_unified_manager hci_management_node solidfire oncommand_insight oncommand_workflow_automation jdk jre e-series_santricity_os_controller +6 more products- EPSS Score: %0.16
- Published: Oct. 20, 2021
- Modified: Aug. 15, 2025
-
6.5
MEDIUMCVE-2018-10951
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.... Read more
- EPSS Score: %0.39
- Published: May. 10, 2018
- Modified: Aug. 15, 2025
-
6.1
MEDIUMCVE-2018-6882
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Lo... Read more
Affected Products : zimbra_collaboration_suite- Actively Exploited
- EPSS Score: %65.60
- Published: Mar. 27, 2018
- Modified: Aug. 15, 2025
-
10.0
HIGHCVE-2018-7445
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before... Read more
Affected Products : routeros- Actively Exploited
- EPSS Score: %87.80
- Published: Mar. 19, 2018
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2019-3924
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerabi... Read more
Affected Products : routeros- EPSS Score: %12.22
- Published: Feb. 20, 2019
- Modified: Aug. 15, 2025
-
8.8
HIGHCVE-2020-15841
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDA... Read more
- EPSS Score: %0.34
- Published: Jul. 20, 2020
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2021-21000
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware 750-891_firmware 750-823_firmware +44 more products- EPSS Score: %0.13
- Published: May. 24, 2021
- Modified: Aug. 15, 2025
-
9.1
CRITICALCVE-2021-21001
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware 750-891_firmware 750-823_firmware +44 more products- EPSS Score: %0.24
- Published: May. 24, 2021
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2021-30186
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware plcwinnt runtime_toolkit +46 more products- EPSS Score: %0.45
- Published: May. 25, 2021
- Modified: Aug. 15, 2025
-
6.5
MEDIUMCVE-2025-45317
A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive.... Read more
Affected Products : hortusfox- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-50615
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_mac_filter_set in the payload, which can cause the... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-50616
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_advanced_set in the payload, which can cause the p... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-50617
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wps_set in the payload, which can cause the program t... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-45313
A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.... Read more
Affected Products : hortusfox- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8926
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be laun... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-47716
IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. IBM X-Force ID: 271656.... Read more
- Published: Mar. 01, 2024
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-55197
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used on a malicious cross-refere... Read more
Affected Products : pypdf- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2023-43043
IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.... Read more
- Published: Mar. 13, 2024
- Modified: Aug. 15, 2025
-
4.3
MEDIUMCVE-2024-1504
The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5.1. This is due to missing or incorrect nonce validation on the secupress_blackhole_ban_ip() function. This... Read more
Affected Products : secupress- Published: Apr. 02, 2024
- Modified: Aug. 15, 2025
-
6.1
MEDIUMCVE-2024-53989
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with cer... Read more
- Published: Dec. 02, 2024
- Modified: Aug. 15, 2025