Latest CVE Feed
-
7.5
HIGHCVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has ... Read more
- Published: Jun. 26, 2019
- Modified: Sep. 12, 2025
-
9.8
CRITICALCVE-2019-5312
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.... Read more
Affected Products : wxjava- Published: Jan. 04, 2019
- Modified: Sep. 12, 2025
-
9.8
CRITICALCVE-2023-42276
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.... Read more
Affected Products : hutool- Published: Sep. 08, 2023
- Modified: Sep. 12, 2025
-
7.8
HIGHCVE-2025-50674
An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.... Read more
Affected Products : openmediavault- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2023-51080
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.... Read more
Affected Products : hutool- Published: Dec. 27, 2023
- Modified: Sep. 12, 2025
-
8.1
HIGHCVE-2025-51605
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. ... Read more
Affected Products : shopizer- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-53496
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.... Read more
Affected Products : my-site- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-52085
An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but no... Read more
Affected Products : yoosee- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-52287
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.... Read more
Affected Products : elite- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
7.3
HIGHCVE-2025-55581
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or pe... Read more
- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2025-55192
HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home As... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-25293
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress S... Read more
- Published: Mar. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-25292
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differ... Read more
- Published: Mar. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25291
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differ... Read more
- Published: Mar. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-10323
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. Th... Read more
Affected Products :- Published: Sep. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-55454
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : dootask- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-57801
gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulnerability. Because ... Read more
- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cryptography
-
3.5
LOWCVE-2025-55455
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.... Read more
Affected Products : dootask- Published: Aug. 22, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-54261
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.... Read more
Affected Products : coldfusion- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2023-51074
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.... Read more
Affected Products : jayway_jsonpath- Published: Dec. 27, 2023
- Modified: Sep. 12, 2025