Latest CVE Feed
-
6.5
MEDIUMCVE-2024-42048
OpenOrange Business Framework 1.15.5 provides unprivileged users with write access to the installation directory.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
9.4
CRITICALCVE-2025-34149
A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. E... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34151
A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthentica... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-55138
LinkJoin through 882f196 mishandles token ownership in password reset.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-51533
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-8698
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to reac... Read more
Affected Products : open5gs- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-47908
Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This behavior can be abused by attackers to produce undue... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.0
HIGHCVE-2025-47907
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition ... Read more
Affected Products : go- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Race Condition
-
2.3
LOWCVE-2025-54799
Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike th... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
2.5
LOWCVE-2025-54798
tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2025-8194
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the p... Read more
Affected Products : python- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2022-3109
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.... Read more
- EPSS Score: %0.23
- Published: Dec. 16, 2022
- Modified: Aug. 07, 2025
-
5.3
MEDIUMCVE-2022-3341
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer derefere... Read more
- EPSS Score: %0.05
- Published: Jan. 12, 2023
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2024-10455
Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block... Read more
Affected Products : ud3tn- Published: Oct. 28, 2024
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2024-31409
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.... Read more
Affected Products : powerpanel- Published: May. 15, 2024
- Modified: Aug. 07, 2025
-
4.4
MEDIUMCVE-2024-1040
Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the device.... Read more
- EPSS Score: %0.01
- Published: Feb. 01, 2024
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2024-1039
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.... Read more
- EPSS Score: %0.12
- Published: Feb. 01, 2024
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2024-8185
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of... Read more
- Published: Oct. 31, 2024
- Modified: Aug. 07, 2025
-
6.5
MEDIUMCVE-2024-20457
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulne... Read more
Affected Products : unified_communications_manager_im_and_presence_service- Published: Nov. 06, 2024
- Modified: Aug. 07, 2025
-
3.3
LOWCVE-2021-34951
Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exp... Read more
- Published: May. 07, 2024
- Modified: Aug. 07, 2025