Latest CVE Feed
-
4.3
MEDIUMCVE-2024-6324
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.... Read more
Affected Products : gitlab- Published: Jan. 09, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2025-8535
A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-8109
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.... Read more
Affected Products : ddk- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6077
Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-54871
Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment va... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Misconfiguration
-
7.9
HIGHCVE-2025-54803
js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a mal... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-54802
pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in pyLoad-ng CNL Blueprint via package parameter, allowing Arbitrary File Write which leads to Remo... Read more
Affected Products : pyload- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
7.7
HIGHCVE-2025-53395
Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSvr.dll located in the same directory. When a user with administrative privile... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-53394
Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privil... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-51534
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-50754
Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in the admin panel when viewed by an administrator. This allows attackers to hijack t... Read more
Affected Products :- Published: Aug. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2013-10051
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and ex... Read more
Affected Products : instantcms- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2025-46654
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.... Read more
- Published: Apr. 26, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13041
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overri... Read more
Affected Products : gitlab- Published: Jan. 09, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2024-20407
A vulnerability in the interaction between the TCP Intercept feature and the Snort 3 detection engine on Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies on an affected system. Dev... Read more
Affected Products : firepower_threat_defense- Published: Oct. 23, 2024
- Modified: Aug. 05, 2025
-
6.5
MEDIUMCVE-2024-20515
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data prot... Read more
Affected Products : identity_services_engine- Published: Oct. 02, 2024
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8497
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cusfindphar2.php. The manipulation of the argument Search leads to sql injection. The attack... Read more
Affected Products : online_medicine_guide- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-20275
A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating... Read more
- Published: Oct. 23, 2024
- Modified: Aug. 05, 2025
-
5.5
MEDIUMCVE-2024-20274
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-ge... Read more
- Published: Oct. 23, 2024
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8498
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been classified as critical. This affects an unknown part of the file /cart/index.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate t... Read more
Affected Products : online_medicine_guide- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection