Latest CVE Feed
-
4.9
MEDIUMCVE-2025-8402
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.... Read more
Affected Products : mattermost_server- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
9.1
CRITICALCVE-2024-45438
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET ... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
6.9
MEDIUMCVE-2025-43754
Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows attacke... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
9.8
CRITICALCVE-2025-52352
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functio... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
3.5
LOWCVE-2025-55523
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
6.9
MEDIUMCVE-2025-57768
Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Planned Hours field when creating a new project. When sending a POST request to /issues/ne... Read more
Affected Products : phproject- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.1
HIGHCVE-2024-50641
An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
7.3
HIGHCVE-2025-55524
Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
7.8
HIGHCVE-2025-38743
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevati... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.4
HIGHCVE-2010-20111
Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate input length, resu... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.7
HIGHCVE-2010-20109
Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input,... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.6
HIGHCVE-2010-20119
CommuniCrypt Mail versions up to and including 1.16 contains a stack-based buffer overflow vulnerability in its ANSMTP.dll and AOSMTP.dll ActiveX controls, specifically within the AddAttachments() method. This method fails to properly validate the lengt... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
9.8
CRITICALCVE-2025-53763
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : office_purview_data_governance- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.7
HIGHCVE-2025-27721
Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthorized access to system resources.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
4.8
MEDIUMCVE-2025-55105
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potential... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
5.3
MEDIUMCVE-2025-55229
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +3 more products- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
4.8
MEDIUMCVE-2025-55103
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potential... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
4.8
MEDIUMCVE-2025-55106
There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 that may allow a remote, authenticated attacker to inject malicious a file with an embedded xss script which when loaded could potential... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.5
HIGHCVE-2010-20007
Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long filen... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
-
8.5
HIGHCVE-2010-20107
A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response containing an overly long fil... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025