Latest CVE Feed
-
7.5
HIGHCVE-2025-1477
An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted pa... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2024-12303
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issu... Read more
Affected Products : gitlab- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-47950
CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream... Read more
Affected Products : coredns- Published: Jun. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
0.0
NACVE-2025-38500
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fa... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-36604
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-36605
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). An ... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-36606
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating sys... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-36607
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system com... Read more
Affected Products : unity_operating_environment- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-51390
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.... Read more
- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-50592
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.... Read more
Affected Products : seacms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-52237
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.... Read more
Affected Products : sscms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
6.7
MEDIUMCVE-2025-21017
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
4.4
MEDIUMCVE-2025-21018
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-21019
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.... Read more
Affected Products : health- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-21020
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2025-21021
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Aug. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-49559
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature b... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
5.9
MEDIUMCVE-2025-49558
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could explo... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2025-49556
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-49555
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a vic... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Request Forgery