Latest CVE Feed
-
6.1
MEDIUMCVE-2025-51501
Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows execution of arbitrary JavaScript.... Read more
- Published: Aug. 01, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-51502
Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScript execution in the context of authenticated admin users.... Read more
- Published: Aug. 01, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-51504
Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.... Read more
- Published: Aug. 01, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-32829
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectCrossCommunications' method. This could allow an authenticated remot... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32830
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to byp... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32831
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectUserRights' method. This could allow an authenticated remote attac... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32832
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectUserRights' method. This could allow an authenticated remote attacke... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32833
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProjectUserRights' method. This could allow an authenticated remote attac... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32834
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariablesWithImport' method. This could allow an authenticated ... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32835
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariableArchivingBuffering' method. This could allow an authent... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32836
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetConnectionVariables' method. This could allow an authenticated remote attack... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32837
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveConnectionVariables' method. This could allow an authenticated remote ... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32838
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportConnectionVariables' method. This could allow an authenticated remote att... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32839
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetGateways' method. This could allow an authenticated remote attacker to bypas... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32840
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockGateway' method. This could allow an authenticated remote attacker to bypas... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32841
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockGateway' method. This could allow an authenticated remote attacker to byp... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32842
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetUsers' method. This could allow an authenticated remote attacker to bypass a... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32843
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockUser' method. This could allow an authenticated remote attacker to bypass a... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2024-42472
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to,... Read more
- Published: Aug. 15, 2024
- Modified: Aug. 19, 2025
-
5.4
MEDIUMCVE-2024-25633
eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accounts. A vulnerability has been found starting in version 4.4.0 and prior to version 5.0.0 that allows regula... Read more
Affected Products : elabftw- Published: Aug. 15, 2024
- Modified: Aug. 19, 2025