Latest CVE Feed
-
5.4
MEDIUMCVE-2025-20331
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of u... Read more
Affected Products : identity_services_engine- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-20332
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrato... Read more
Affected Products : identity_services_engine- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-30127
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-8665
A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library libs/agno/agno/tools/mcp.py of the component Model Context Protocol Handler. The manipula... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
7.6
HIGHCVE-2025-51624
Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-2878
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by craftin... Read more
Affected Products : gitlab- Published: Feb. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-12379
A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes paramet... Read more
Affected Products : gitlab- Published: Feb. 12, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-1072
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content usi... Read more
Affected Products : gitlab- Published: Feb. 07, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-20139
A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to... Read more
Affected Products : enterprise_chat_and_email- Published: Apr. 02, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-20165
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper... Read more
- Published: Jan. 22, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-10396
An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client Fet... Read more
Affected Products : openafs- Published: Nov. 14, 2024
- Modified: Aug. 06, 2025
-
5.5
MEDIUMCVE-2024-41751
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Jul. 23, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-41750
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Jul. 23, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-5301
Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit thi... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025
-
7.8
HIGHCVE-2024-5302
Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025
-
7.8
HIGHCVE-2024-5303
Kofax Power PDF PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025
-
7.8
HIGHCVE-2024-5304
Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulne... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025
-
6.1
MEDIUMCVE-2024-40686
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks ag... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Jul. 23, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2024-5305
Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit th... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025
-
7.8
HIGHCVE-2024-5306
Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnera... Read more
- Published: Jun. 06, 2024
- Modified: Aug. 06, 2025