Latest CVE Feed
-
8.8
HIGHCVE-2025-40738
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and po... Read more
Affected Products : sinec_nms- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-40737
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP files. This could allow an attacker to write arbitrary files to restricted locations and po... Read more
Affected Products : sinec_nms- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-40736
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative credentials. This could allow an unauthenticated attacker to reset the superadm... Read more
Affected Products : sinec_nms- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-40735
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.... Read more
Affected Products : sinec_nms- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-3737
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOver. The manipulation of the argument dir leads to path traversal. The attac... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2024-3736
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adminPage/main/upload. The manipulation leads to unrestricted upload. The attack can be la... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-57728
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files... Read more
Affected Products : intellij_idea- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-57727
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference... Read more
Affected Products : intellij_idea- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-40741
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted CFG files. This could allow an attacker to execute code in t... Read more
Affected Products : solid_edge- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-40740
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attac... Read more
Affected Products : solid_edge- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-40739
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attac... Read more
Affected Products : solid_edge- Published: Jul. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-28447
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cgi.... Read more
- Published: Mar. 19, 2024
- Modified: Aug. 21, 2025
-
6.1
MEDIUMCVE-2025-57703
DIAEnergie - Reflected Cross-site Scripting... Read more
Affected Products : diaenergie- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-57702
DIAEnergie - Reflected Cross-site Scripting... Read more
Affected Products : diaenergie- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-57701
DIAEnergie - Reflected Cross-site Scripting... Read more
Affected Products : diaenergie- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGH- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-55503
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-55483
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-51488
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious HTML payload in the Name parameter when creating a new Admin.... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2025-51487
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting