Latest CVE Feed
-
8.7
HIGHCVE-2025-6186
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-5819
An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under cer... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-2937
An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdo... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-2614
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted cont... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-1051
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. ... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-2498
An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP ... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-1477
An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted pa... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2024-12303
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issu... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-47950
CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream... Read more
Affected Products : coredns- Published: Jun. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
0.0
NACVE-2025-38500
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fa... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-36604
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-36605
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). An ... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-36606
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating sys... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-36607
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system com... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-51390
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.... Read more
- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-50592
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.... Read more
Affected Products : seacms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-52237
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.... Read more
Affected Products : sscms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
6.7
MEDIUMCVE-2025-21017
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
4.4
MEDIUMCVE-2025-21018
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-21019
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.... Read more
Affected Products : health- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization