Latest CVE Feed
-
7.5
HIGHCVE-2025-54138
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php endpo... Read more
Affected Products : librenms- Published: Jul. 22, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-7701
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.... Read more
Affected Products : toolkit- Published: Dec. 15, 2024
- Modified: Aug. 05, 2025
-
6.1
MEDIUMCVE-2024-12326
Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scripting. This was done by storing the MIME type of a file and preventing the browser preview for MIME type image... Read more
Affected Products : jirafeau- Published: Dec. 06, 2024
- Modified: Aug. 05, 2025
-
7.5
HIGHCVE-2024-12107
Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS... Read more
Affected Products : ud3tn- Published: Dec. 04, 2024
- Modified: Aug. 05, 2025
-
7.2
HIGHCVE-2025-46123
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memor... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-46122
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46121
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A re... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-46120
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates o... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
6.3
MEDIUMCVE-2025-46119
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrato... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-46118
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remot... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-46117
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its ... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-54141
ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesyst... Read more
Affected Products : viewvc- Published: Jul. 22, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-46116
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` vi... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-51535
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-50420
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-46206
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `st... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-8370
A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown function of the file /intranet/educar_escolaridade_lst.php. The manipulation of the argument descricao leads to cross site scripting. It is ... Read more
Affected Products : i-educar- Published: Jul. 31, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-1473
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the ma... Read more
Affected Products : mlflow- Published: Mar. 20, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-31490
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows SSRF due to DNS Rebinding in requests wrapper. AutoGPT is built with a wrapper ... Read more
- Published: Apr. 14, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
8.6
HIGHCVE-2025-31491
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows of leakage of cross-domain cookies and protected headers in requests redirect. ... Read more
- Published: Apr. 15, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure