Latest CVE Feed
-
7.8
HIGHCVE-2023-35715
Ashlar-Vellum Cobalt AR File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit ... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-35716
Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit th... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2025-2023
Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2021
Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2019
Ashlar-Vellum Cobalt VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to e... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2022
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this v... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2020
Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit ... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2018
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this v... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2014
Ashlar-Vellum Cobalt VS File Parsing Use of Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-2012
Ashlar-Vellum Cobalt VS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit th... Read more
Affected Products : cobalt- Published: Mar. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2023-39329
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.... Read more
- Published: Jul. 13, 2024
- Modified: Aug. 08, 2025
-
4.3
MEDIUMCVE-2023-39327
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.... Read more
- Published: Jul. 13, 2024
- Modified: Aug. 08, 2025
-
9.8
CRITICALCVE-2025-8504
A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to init... Read more
Affected Products : kitchen_treasure- Published: Aug. 03, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8496
A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /viewform.php. The manipulation of the argument ID leads to sql injection. The a... Read more
Affected Products : online_admission_system- Published: Aug. 03, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8495
A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injectio... Read more
Affected Products : intern_membership_management_system- Published: Aug. 03, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-7907
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/resources/application-druid.yml of the component Druid. The manipulation leads to use of ... Read more
Affected Products : ruoyi- Published: Jul. 20, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-7911
A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-ba... Read more
- Published: Jul. 20, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-7902
A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/web/controller/system/SysNoticeController.java. The manipulation leads to cross site scripting. It is possi... Read more
Affected Products : ruoyi- Published: Jul. 20, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-52372
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components.... Read more
Affected Products : hmailserver- Published: Jul. 21, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2024-6519
A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI Host Bus Adapter emulation. This issue can lead to a crash or VM escape.... Read more
Affected Products : qemu- Published: Oct. 21, 2024
- Modified: Aug. 08, 2025