Latest CVE Feed
-
3.1
LOWCVE-2025-8751
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scriptin... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.8
MEDIUMCVE-2025-8746
A vulnerability, which was classified as problematic, was found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclose... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.7
MEDIUMCVE-2025-55149
Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the revi... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-55152
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwa... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
5.1
MEDIUMCVE-2025-8765
A vulnerability classified as problematic was found in Datacom DM955 5GT 1200 825.8010.00. Affected by this vulnerability is an unknown functionality of the component Wireless Basic Settings. The manipulation of the argument SSID leads to cross site scrip... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
7.3
HIGHCVE-2025-8757
A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the component Embedded Boa Web Server. The manipulation leads to least privilege vio... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.3
MEDIUMCVE-2025-55006
Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScri... Read more
Affected Products : frappe_lms- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
7.1
HIGHCVE-2025-55009
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions 0.14.1 and below, @workos-inc/authkit-remix exposed sensitive authentication artifacts — specifically sealed... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
2.0
LOWCVE-2025-4655
SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 G... Read more
- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.8
MEDIUMCVE-2025-8750
A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the component Add Product Page. The manipulation of the argument File leads to ... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.3
MEDIUMCVE-2025-8759
A vulnerability was found in TRENDnet TN-200 1.02b02. It has been declared as problematic. This vulnerability affects unknown code of the component Lighttpd. The manipulation of the argument secdownload.secret with the input neV3rUseMe leads to use of har... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
4.3
MEDIUMCVE-2025-7965
The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2025-8853
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
7.0
HIGHCVE-2025-8863
YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
9.3
CRITICALCVE-2012-10038
Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These file... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
4.1
MEDIUMCVE-2025-8865
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in ... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2025-45146
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
6.5
MEDIUMCVE-2025-8841
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads ... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-8842
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-8843
A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been ... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025