Latest CVE Feed
-
7.8
HIGHCVE-2025-1046
Luxion KeyShot SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerabilit... Read more
Affected Products : keyshot- Published: Apr. 23, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-1047
Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit ... Read more
Affected Products : keyshot- Published: Apr. 23, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
8.0
HIGHCVE-2025-1520
PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PostHog. Authentication is required to exploit this vulnerabi... Read more
Affected Products : posthog- Published: Apr. 23, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-1521
PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PostHog. Authentication is required to exploit this ... Read more
Affected Products : posthog- Published: Apr. 23, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
3.1
LOWCVE-2023-42119
Exim dnsdb Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Exim. Authentication is not required to exploit this vulnerability. Th... Read more
Affected Products : exim- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
8.8
HIGHCVE-2023-42118
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. T... Read more
- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
6.1
MEDIUMCVE-2024-45515
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can expl... Read more
Affected Products : collaboration- Published: Jul. 30, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-43720
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.... Read more
Affected Products : headwind_mdm- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2025-1522
PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PostHog. Authentication is required to exploit this vulnera... Read more
Affected Products : posthog- Published: Apr. 23, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-55040
Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-43977
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCa... Read more
Affected Products : com.skt.prod.dialer- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-43976
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.Di... Read more
Affected Products : 2ndline- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-26901
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1.... Read more
Affected Products : brizy- Published: Apr. 09, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2023-42117
Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. Th... Read more
Affected Products : exim- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2023-42116
Exim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The... Read more
Affected Products : exim- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
4.3
MEDIUMCVE-2021-34751
A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive configuration information. The attacker would require low privi... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 07, 2025
-
5.8
MEDIUMCVE-2021-34753
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. This vulnerability ... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2023-42115
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw ex... Read more
Affected Products : exim- Published: May. 03, 2024
- Modified: Aug. 07, 2025
-
7.2
HIGHCVE-2024-5579
Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerabi... Read more
Affected Products : allegra- Published: Nov. 22, 2024
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2025-52364
Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network... Read more
- Published: Jul. 09, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration