Latest CVE Feed
-
4.4
MEDIUMCVE-2025-6241
LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malic... Read more
Affected Products :- Published: Jul. 27, 2025
- Modified: Jul. 30, 2025
-
4.8
MEDIUMCVE-2025-20307
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability i... Read more
- Published: Jul. 02, 2025
- Modified: Jul. 30, 2025
-
9.0
HIGHCVE-2021-25297
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP... Read more
Affected Products : nagios_xi- Actively Exploited
- EPSS Score: %54.52
- Published: Feb. 15, 2021
- Modified: Jul. 30, 2025
-
5.8
MEDIUMCVE-2024-20261
A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive fi... Read more
Affected Products : firepower_threat_defense- Published: May. 22, 2024
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2021-30663
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execut... Read more
- Actively Exploited
- EPSS Score: %0.12
- Published: Sep. 08, 2021
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2025-8011
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.... Read more
Affected Products : manageengine_adselfservice_plus- Actively Exploited
- EPSS Score: %94.42
- Published: Sep. 07, 2021
- Modified: Jul. 30, 2025
-
7.8
HIGHCVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could u... Read more
Affected Products : linux_kernel enterprise_linux fedora enterprise_linux_server_aus enterprise_linux_server_tus h410c_firmware enterprise_linux_eus h300s_firmware h500s_firmware h700s_firmware +29 more products- Actively Exploited
- EPSS Score: %84.35
- Published: Mar. 10, 2022
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2022-24990
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.... Read more
- Actively Exploited
- EPSS Score: %94.40
- Published: Feb. 07, 2023
- Modified: Jul. 30, 2025
-
4.8
MEDIUMCVE-2025-6050
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before includi... Read more
Affected Products : mezzanine- Published: Jun. 17, 2025
- Modified: Jul. 30, 2025
-
6.1
MEDIUMCVE-2022-27926
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.... Read more
Affected Products : collaboration- Actively Exploited
- EPSS Score: %94.28
- Published: Apr. 21, 2022
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2022-33891
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path ... Read more
Affected Products : spark- Actively Exploited
- EPSS Score: %93.10
- Published: Jul. 18, 2022
- Modified: Jul. 30, 2025
-
9.6
CRITICALCVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.... Read more
- Actively Exploited
- EPSS Score: %1.33
- Published: Sep. 26, 2022
- Modified: Jul. 30, 2025
-
5.8
MEDIUMCVE-2024-20293
A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offere... Read more
- Published: May. 22, 2024
- Modified: Jul. 30, 2025
-
5.0
MEDIUMCVE-2024-20355
A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to su... Read more
- Published: May. 22, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2018-1273
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can... Read more
- Actively Exploited
- EPSS Score: %94.01
- Published: Apr. 11, 2018
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-2244
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger... Read more
Affected Products : gravityzone- Published: Apr. 04, 2025
- Modified: Jul. 30, 2025
-
7.3
HIGHCVE-2025-2243
A server-side request forgery (SSRF) vulnerability in Bitdefender GravityZone Console allows an attacker to bypass input validation logic using leading characters in DNS requests. Paired with other potential vulnerabilities, this bypass could be used for ... Read more
Affected Products : gravityzone- Published: Apr. 04, 2025
- Modified: Jul. 30, 2025
-
7.8
HIGHCVE-2019-0880
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 windows_10_1809 windows_10_1507 +6 more products- Actively Exploited
- EPSS Score: %1.37
- Published: Jul. 15, 2019
- Modified: Jul. 30, 2025
-
6.5
MEDIUMCVE-2019-6693
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data... Read more
Affected Products : fortios- Actively Exploited
- EPSS Score: %74.88
- Published: Nov. 21, 2019
- Modified: Jul. 30, 2025