Latest CVE Feed
-
10.0
CRITICALCVE-2025-55169
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This... Read more
Affected Products : wegia- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-55168
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/saude/aplicar_medicamento.php endpoint, specifically in the id_ficha... Read more
Affected Products : wegia- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-36000
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent... Read more
Affected Products : websphere_application_server- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-30907
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecuPress SecuPress Free allows DOM-Based XSS. This issue affects SecuPress Free: from n/a through 2.2.5.3.... Read more
Affected Products : secupress- Published: Mar. 27, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.0
MEDIUMCVE-2024-22349
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Jan. 20, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-36124
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration... Read more
Affected Products : websphere_application_server- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-49568
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-49567
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in servi... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-49564
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-49563
Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2025-32766
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands... Read more
Affected Products : fortiweb- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-22347
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
- Published: Jan. 20, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cryptography
-
6.7
MEDIUMCVE-2025-27759
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated priv... Read more
Affected Products : fortiweb- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-25248
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versi... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-49758
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-49759
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-53727
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-47954
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : sql_server_2022- Published: Aug. 12, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-51462
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.... Read more
Affected Products : qradar_wincollect- Published: Jan. 17, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-51465
IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more
- Published: Dec. 04, 2024
- Modified: Aug. 14, 2025