Latest CVE Feed
-
8.6
HIGHCVE-2024-20339
A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vuln... Read more
- Published: Oct. 23, 2024
- Modified: Aug. 08, 2025
-
8.1
HIGHCVE-2025-24472
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstre... Read more
- Actively Exploited
- Published: Feb. 11, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-54021
An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter ... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-48884
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiOS versions 7.6.0, 7.4.0 through 7.4.4, 7.2.5 through 7.2.9, 7.0.0 through 7.0.15, 6.4.0 thro... Read more
Affected Products : fortimanager fortios fortiproxy fortiweb fortivoice fortirecorder fortimanager_cloud- Published: Jan. 14, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-45663
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.... Read more
Affected Products : db2- Published: Nov. 21, 2024
- Modified: Aug. 08, 2025
-
9.6
CRITICALCVE-2024-6246
Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not requ... Read more
- Published: Nov. 22, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-34301
Ashlar-Vellum Cobalt CO File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
6.8
MEDIUMCVE-2024-6247
Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploi... Read more
- Published: Nov. 22, 2024
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8701
A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /OL_OprationLog/GetPageList. The manipulation of the argument optU... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-50675
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
7.0
HIGHCVE-2025-26513
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-22963
Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.... Read more
Affected Products : teedy- Published: Jan. 13, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2024-6248
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not require... Read more
- Published: Nov. 22, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-34309
Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vu... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-35714
Ashlar-Vellum Cobalt IGS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit t... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.0
HIGHCVE-2023-34305
Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerabilit... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-34304
Ashlar-Vellum Cobalt Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerabili... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-34300
Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2023-34299
Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to ex... Read more
Affected Products : cobalt- Published: May. 03, 2024
- Modified: Aug. 08, 2025
-
7.0
HIGHCVE-2025-5222
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.... Read more
- Published: May. 27, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption