Latest CVE Feed
-
5.1
MEDIUMCVE-2025-7020
An incorrect encryption implementation vulnerability exists in the system log dump feature of BYD's DiLink 3.0 OS (e.g. in the model ATTO3). An attacker with physical access to the vehicle can bypass the encryption of log dumps on the In-Vehicle Infotainm... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
7.1
HIGHCVE-2025-55008
The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifi... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
8.7
HIGHCVE-2025-54888
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 th... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
8.0
HIGHCVE-2025-54063
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a malicious website... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.1
MEDIUMCVE-2025-8866
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addre... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.6
MEDIUMCVE-2025-8660
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-8852
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to in... Read more
Affected Products : wukongcrm- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
7.0
HIGHCVE-2025-8862
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.5
MEDIUMCVE-2025-8840
A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the att... Read more
Affected Products : jsherp- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
4.8
MEDIUMCVE-2025-8844
A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has b... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
4.8
MEDIUMCVE-2025-8834
A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wireless/basic.asp of the component Wireless Basic Settings Page. The manipulation of the argument Network Name leads to cross site script... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
9.0
HIGHCVE-2025-8826
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function um_rp_autochannel of the file /goform/RP_setBasicAuto. The manipulation of the argument apcli_AuthMode_2G/a... Read more
Affected Products : re6500_firmware re6300_firmware re9000_firmware re6250_firmware re6350_firmware re7000_firmware- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-8808
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to c... Read more
Affected Products :- Published: Aug. 10, 2025
- Modified: Aug. 11, 2025
-
3.1
LOWCVE-2025-8751
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scriptin... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.8
MEDIUMCVE-2025-8746
A vulnerability, which was classified as problematic, was found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclose... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.7
MEDIUMCVE-2025-55149
Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the revi... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-55152
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwa... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
5.1
MEDIUMCVE-2025-8765
A vulnerability classified as problematic was found in Datacom DM955 5GT 1200 825.8010.00. Affected by this vulnerability is an unknown functionality of the component Wireless Basic Settings. The manipulation of the argument SSID leads to cross site scrip... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
7.3
HIGHCVE-2025-8757
A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the component Embedded Boa Web Server. The manipulation leads to least privilege vio... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.3
MEDIUMCVE-2025-55006
Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScri... Read more
Affected Products : frappe_lms- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025