Latest CVE Feed
-
6.7
MEDIUMCVE-2025-21021
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-49559
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature b... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
5.9
MEDIUMCVE-2025-49558
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could explo... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2025-49556
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-49555
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a vic... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-49554
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2022-29376
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.... Read more
- EPSS Score: %0.55
- Published: May. 23, 2022
- Modified: Aug. 15, 2025
-
9.4
CRITICALCVE-2025-8876
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.... Read more
Affected Products : n-central- Actively Exploited
- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-8875
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.... Read more
Affected Products : n-central- Actively Exploited
- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-49353
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.... Read more
Affected Products : watson_assistant_for_ibm_cloud_pak_for_data- Published: Nov. 26, 2024
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2025-46199
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields... Read more
Affected Products : grav- Published: Jul. 25, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-54445
Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Aug. 15, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2025-8031
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird... Read more
- Published: Jul. 22, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2024-40681
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security restrictions and execute actions against the queue manager.... Read more
- Published: Sep. 07, 2024
- Modified: Aug. 15, 2025
-
7.6
HIGHCVE-2024-42346
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javas... Read more
Affected Products : galaxy- Published: Sep. 20, 2024
- Modified: Aug. 15, 2025
-
9.1
CRITICALCVE-2024-42351
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tamper... Read more
Affected Products : galaxy- Published: Sep. 20, 2024
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-8805
A vulnerability was determined in Open5GS up to 2.7.5. Affected by this issue is the function smf_gsm_state_wait_pfcp_deletion of the file src/smf/gsm-sm.c of the component SMF. The manipulation leads to denial of service. The attack may be launched remot... Read more
Affected Products : open5gs- Published: Aug. 10, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-8804
A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ngap_build_downlink_nas_transport of the component AMF. The manipulation leads to reachable assertion. The attack can be launched remotely. The exploit has be... Read more
Affected Products : open5gs- Published: Aug. 10, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-8802
A vulnerability was determined in Open5GS up to 2.7.5. This vulnerability affects the function smf_state_operational of the file src/smf/smf-sm.c of the component SMF. The manipulation of the argument stream leads to denial of service. The attack can be i... Read more
Affected Products : open5gs- Published: Aug. 10, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-8801
A vulnerability was found in Open5GS up to 2.7.5. This affects the function gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has... Read more
Affected Products : open5gs- Published: Aug. 10, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service