Latest CVE Feed
-
5.1
MEDIUMCVE-2025-8519
A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of the file /vadmin123/index.php?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to i... Read more
Affected Products : vvveb- Published: Aug. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
5.8
MEDIUMCVE-2025-8520
A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component Drag-and-Drop Editor. The manipulation of the argument url leads to server-... Read more
Affected Products : vvveb- Published: Aug. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Server-Side Request Forgery
-
5.0
MEDIUMCVE-2025-8522
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to la... Read more
Affected Products : vvvebjs- Published: Aug. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2025-8521
A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects some unknown processing of the file /vadmin123/index.php?module=settings/post-types of the component Add Type Handler. The manipulation le... Read more
Affected Products : vvveb- Published: Aug. 04, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-41130
llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.... Read more
- Published: Jul. 22, 2024
- Modified: Aug. 27, 2025
-
5.9
MEDIUMCVE-2024-6388
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.... Read more
Affected Products : ubuntu_advantage_desktop_daemon- Published: Jun. 27, 2024
- Modified: Aug. 27, 2025
-
5.5
MEDIUMCVE-2015-7313
LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.... Read more
Affected Products : libtiff- Published: Mar. 17, 2017
- Modified: Aug. 27, 2025
-
6.4
MEDIUMCVE-2024-2165
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products : seopress- Published: Apr. 09, 2024
- Modified: Aug. 27, 2025
-
8.8
HIGHCVE-2024-2125
The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it po... Read more
Affected Products : envialosimple- Published: Apr. 09, 2024
- Modified: Aug. 27, 2025
-
8.8
HIGHCVE-2024-29169
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on t... Read more
Affected Products : secure_connect_gateway- Published: Jun. 13, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-29152
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband so... Read more
- Published: Jun. 04, 2024
- Modified: Aug. 27, 2025
-
8.4
HIGHCVE-2024-27372
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from us... Read more
- Published: Jun. 05, 2024
- Modified: Aug. 27, 2025
-
9.9
CRITICALCVE-2024-24830
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated reg... Read more
Affected Products : openobserve- Published: Feb. 08, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2024-24731
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the htt... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Memory Corruption
-
5.9
MEDIUMCVE-2023-48368
Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 27, 2025
-
5.5
MEDIUMCVE-2023-47169
Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 27, 2025
-
7.5
HIGHCVE-2025-54939
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.... Read more
- Published: Aug. 01, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Memory Corruption
-
2.1
LOWCVE-2013-4229
Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page settings.... Read more
- Published: Aug. 21, 2013
- Modified: Aug. 27, 2025
-
6.0
MEDIUMCVE-2013-4230
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to ... Read more
- Published: Aug. 21, 2013
- Modified: Aug. 27, 2025
-
2.6
LOWCVE-2013-4504
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.... Read more
- Published: May. 13, 2014
- Modified: Aug. 27, 2025