Latest CVE Feed
-
10.0
CRITICALCVE-2014-125123
An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize inpu... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
10.0
CRITICALCVE-2014-125124
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p paramet... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.2
CRITICALCVE-2014-125126
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanis... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
7.0
HIGHCVE-2025-34146
A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) condition or, under certa... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
5.3
MEDIUMCVE-2025-54832
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
8.6
HIGHCVE-2025-53022
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of th... Read more
Affected Products :- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
6.9
MEDIUMCVE-2025-54572
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because ... Read more
Affected Products : ruby-saml- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
0.0
NACVE-2025-38498
In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/not ours mounts Ensure that propagation settings can only be changed for mounts located in the caller's mount namespace. This change ali... Read more
Affected Products : linux_kernel- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
7.2
HIGHCVE-2025-41688
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.... Read more
- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
6.5
MEDIUMCVE-2025-8344
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument file... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
10.0
CRITICALCVE-2013-10040
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Onc... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.3
CRITICALCVE-2012-10021
A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via ... Read more
Affected Products : dir-605l_firmware- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-46811
A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with access to the websocket at /rhn/websocket/minion/remote-commands to execute arbitrary commands as root. This issue affects Container suse/manager/5.0/x86_6... Read more
Affected Products :- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
8.1
HIGHCVE-2024-48916
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC ... Read more
Affected Products : ceph- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
6.9
MEDIUMCVE-2025-46809
A Insertion of Sensitive Information into Log File vulnerability in SUSE Multi Linux Manager exposes the HTTP proxy credentials. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
6.9
MEDIUMCVE-2025-43018
Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.... Read more
Affected Products :- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
7.0
HIGHCVE-2025-25011
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this fla... Read more
Affected Products : elastic_beats- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
5.1
MEDIUMCVE-2025-54388
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded... Read more
Affected Products : moby- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
-
6.5
MEDIUMCVE-2024-37100
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3.... Read more
- Published: Jul. 22, 2024
- Modified: Jul. 31, 2025
-
6.3
MEDIUMCVE-2024-10026
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.... Read more
Affected Products : gvisor- Published: Jan. 30, 2025
- Modified: Jul. 31, 2025