Latest CVE Feed
-
4.8
MEDIUMCVE-2025-8919
A vulnerability was determined in Portabilis i-Diario up to 1.6. Affected is an unknown function of the file /objetivos-de-aprendizagem-e-habilidades of the component History Page. The manipulation of the argument código/objetivo habilidade leads to cross... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8286
The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, manipulate data, or factory reset the device.... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2023-50234
Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hancom Office Cell. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2025-52327
SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file... Read more
- Published: Aug. 01, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-4267
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' ... Read more
- Published: May. 22, 2024
- Modified: Aug. 15, 2025
-
7.1
HIGHCVE-2024-43238
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs weMail allows Reflected XSS.This issue affects weMail: from n/a through 1.14.5.... Read more
- Published: Aug. 18, 2024
- Modified: Aug. 15, 2025
-
7.1
HIGHCVE-2024-43958
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gianni Porto IntoTheDark allows Reflected XSS.This issue affects IntoTheDark: from n/a through 1.0.5.... Read more
- Published: Aug. 29, 2024
- Modified: Aug. 15, 2025
-
8.8
HIGHCVE-2024-4403
A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the program without their ... Read more
- Published: Jun. 10, 2024
- Modified: Aug. 15, 2025
-
8.0
HIGHCVE-2024-46486
TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.... Read more
- Published: Oct. 04, 2024
- Modified: Aug. 15, 2025
-
8.4
HIGHCVE-2024-46954
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.... Read more
Affected Products : ghostscript- Published: Nov. 10, 2024
- Modified: Aug. 15, 2025
-
8.0
HIGHCVE-2024-48288
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.... Read more
- Published: Nov. 21, 2024
- Modified: Aug. 15, 2025
-
5.5
MEDIUMCVE-2024-49541
Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 15, 2025
-
4.4
MEDIUMCVE-2024-6971
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such ... Read more
- Published: Oct. 11, 2024
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2025-2013
Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this v... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-20180
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a u... Read more
Affected Products : secure_email_and_web_manager asyncos secure_email_gateway secure_email_gateway_virtual_appliance_c100v secure_email_gateway_virtual_appliance_c300v secure_email_gateway_virtual_appliance_c600v secure_email_gateway_c195 secure_email_gateway_c395 secure_email_gateway_c695 secure_email_and_web_manager_virtual_appliance_m100v +13 more products- Published: Feb. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-0844
The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. This makes it possible for authenticated attackers, with administrator-level acc... Read more
- EPSS Score: %0.09
- Published: Feb. 02, 2024
- Modified: Aug. 15, 2025
-
7.8
HIGHCVE-2024-13046
Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit t... Read more
Affected Products : cobalt- Published: Dec. 30, 2024
- Modified: Aug. 15, 2025
-
6.4
MEDIUMCVE-2024-1242
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 4.10.18 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : premium_addons_for_elementor- Published: Feb. 29, 2024
- Modified: Aug. 15, 2025
-
8.8
HIGHCVE-2024-1522
A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate ... Read more
- Published: Mar. 30, 2024
- Modified: Aug. 15, 2025
-
8.2
HIGHCVE-2024-1646
parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict access, which is inadequate when the application is bound to a ... Read more
- Published: Apr. 16, 2024
- Modified: Aug. 15, 2025