Latest CVE Feed
-
8.8
HIGHCVE-2025-53772
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-53769
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.... Read more
Affected Products : windows_security_app- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-53761
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.... Read more
Affected Products : office 365_apps powerpoint office_long_term_servicing_channel office_2024 office_2021 office_2019 powerpoint_2016- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-53760
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Server-Side Request Forgery
-
8.8
HIGHCVE-2025-3486
Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The spe... Read more
Affected Products : allegra- Published: May. 22, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2024-20495
A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in... Read more
- Published: Oct. 23, 2024
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-3884
Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cloudera Hue. Authentication is not required to exploit this vulner... Read more
Affected Products : hue- Published: May. 22, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-3885
Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Harman Becker MGU21 devices. Authentication ... Read more
- Published: May. 22, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-8932
A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated re... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-8770
An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipu... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-7739
An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label d... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-7734
An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by inject... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.7
HIGHCVE-2025-6186
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-5819
An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under cer... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-2937
An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdo... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-2614
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted cont... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-1051
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. ... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-2498
An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP ... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-1477
An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted pa... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2024-12303
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issu... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization