Latest CVE Feed
-
7.2
HIGHCVE-2024-13201
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attach... Read more
Affected Products : springboot-blog- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
5.4
MEDIUMCVE-2024-13202
A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Hand... Read more
Affected Products : springboot-blog- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
8.8
HIGHCVE-2025-0333
A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remot... Read more
Affected Products : cy-fast- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
8.8
HIGHCVE-2025-0334
A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. The manipulation of the argument order leads to sql injection. The attack can be laun... Read more
Affected Products : cy-fast- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
8.8
HIGHCVE-2025-0344
A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /commpara/listData. The manipulation of the argument order leads to sql injection. The attack can be laun... Read more
Affected Products : cy-fast- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
8.8
HIGHCVE-2025-0345
A vulnerability was found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this issue is the function listData of the file /sys/menu/listData. The manipulation of the argument order leads to sql injection. The attack may be launched remotely... Read more
Affected Products : cy-fast- Published: Jan. 09, 2025
- Modified: Aug. 22, 2025
-
8.7
HIGHCVE-2024-45061
A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious... Read more
Affected Products : observium- Published: Jan. 15, 2025
- Modified: Aug. 22, 2025
-
8.7
HIGHCVE-2024-47002
A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.... Read more
Affected Products : observium- Published: Jan. 15, 2025
- Modified: Aug. 22, 2025
-
4.3
MEDIUMCVE-2025-22129
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.173624... Read more
Affected Products : tuleap- Published: Feb. 03, 2025
- Modified: Aug. 22, 2025
-
8.7
HIGHCVE-2024-47140
A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provid... Read more
Affected Products : observium- Published: Jan. 15, 2025
- Modified: Aug. 22, 2025
-
5.4
MEDIUMCVE-2024-52599
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability t... Read more
Affected Products : tuleap- Published: Dec. 09, 2024
- Modified: Aug. 22, 2025
-
7.5
HIGHCVE-2025-36512
A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database inst... Read more
Affected Products : comdb2- Published: Jul. 22, 2025
- Modified: Aug. 22, 2025
-
7.5
HIGHCVE-2025-36520
A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to a denial of service. An attacker can send packets to trigger this vulnerab... Read more
Affected Products : comdb2- Published: Jul. 22, 2025
- Modified: Aug. 22, 2025
-
7.5
HIGHCVE-2025-46354
A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to a denial of service. An attacker can send a malicious packet to trigger th... Read more
Affected Products : comdb2- Published: Jul. 22, 2025
- Modified: Aug. 22, 2025
-
7.5
HIGHCVE-2025-48498
A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An atta... Read more
Affected Products : comdb2- Published: Jul. 22, 2025
- Modified: Aug. 22, 2025
-
7.5
HIGHCVE-2025-35966
A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2 8.1. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instanc... Read more
Affected Products : comdb2- Published: Jul. 22, 2025
- Modified: Aug. 22, 2025
-
9.8
CRITICALCVE-2025-50738
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interactio... Read more
Affected Products : memos- Published: Jul. 29, 2025
- Modified: Aug. 22, 2025
-
7.1
HIGHCVE-2023-32701
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition.... Read more
Affected Products : qnx_software_development_platform- EPSS Score: %0.09
- Published: Nov. 14, 2023
- Modified: Aug. 22, 2025
-
8.1
HIGHCVE-2021-32025
An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2... Read more
Affected Products : qnx_software_development_platform qnx_os_for_medical qnx_os_for_safety qnx_momentics- EPSS Score: %0.04
- Published: Mar. 10, 2022
- Modified: Aug. 22, 2025
-
9.8
CRITICALCVE-2021-22156
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.... Read more
- EPSS Score: %0.65
- Published: Aug. 17, 2021
- Modified: Aug. 22, 2025