Latest CVE Feed
-
8.8
HIGHCVE-2023-35674
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ... Read more
Affected Products : android- Actively Exploited
- EPSS Score: %0.06
- Published: Sep. 11, 2023
- Modified: Jul. 30, 2025
-
8.6
HIGHCVE-2024-20353
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, result... Read more
- Actively Exploited
- Published: Apr. 24, 2024
- Modified: Jul. 30, 2025
-
6.0
MEDIUMCVE-2024-20359
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticat... Read more
- Actively Exploited
- Published: Apr. 24, 2024
- Modified: Jul. 30, 2025
-
8.6
HIGHCVE-2024-24919
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available... Read more
- Actively Exploited
- Published: May. 28, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2024-3273
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Actively Exploited
- Published: Apr. 04, 2024
- Modified: Jul. 30, 2025
-
10.0
CRITICALCVE-2024-51378
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which... Read more
Affected Products : cyberpanel- Actively Exploited
- Published: Oct. 29, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2024-58136
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.... Read more
Affected Products : yii- Actively Exploited
- Published: Apr. 10, 2025
- Modified: Jul. 30, 2025
-
10.0
CRITICALCVE-2025-20281
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vuln... Read more
- Actively Exploited
- Published: Jun. 25, 2025
- Modified: Jul. 30, 2025
-
10.0
CRITICALCVE-2025-32433
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH pr... Read more
Affected Products : staros network_services_orchestrator rv340_firmware rv340w_firmware rv345_firmware rv345p_firmware enterprise_nfv_infrastructure_software erlang\/otp rv160_firmware rv160w_firmware +26 more products- Actively Exploited
- Published: Apr. 16, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2024-34171
Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.... Read more
Affected Products : monitouch_v-sft- Published: May. 30, 2024
- Modified: Jul. 30, 2025
-
7.8
HIGHCVE-2024-20389
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is ... Read more
Affected Products : network_services_orchestrator confd confd_basic crosswork_network_services_orchestrator- Published: May. 16, 2024
- Modified: Jul. 30, 2025
-
4.4
MEDIUMCVE-2025-6241
LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malic... Read more
Affected Products :- Published: Jul. 27, 2025
- Modified: Jul. 30, 2025
-
4.8
MEDIUMCVE-2025-20307
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability i... Read more
- Published: Jul. 02, 2025
- Modified: Jul. 30, 2025
-
9.0
HIGHCVE-2021-25297
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP... Read more
Affected Products : nagios_xi- Actively Exploited
- EPSS Score: %54.52
- Published: Feb. 15, 2021
- Modified: Jul. 30, 2025
-
5.8
MEDIUMCVE-2024-20261
A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive fi... Read more
Affected Products : firepower_threat_defense- Published: May. 22, 2024
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2021-30663
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execut... Read more
- Actively Exploited
- EPSS Score: %0.12
- Published: Sep. 08, 2021
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2025-8011
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.... Read more
Affected Products : manageengine_adselfservice_plus- Actively Exploited
- EPSS Score: %94.42
- Published: Sep. 07, 2021
- Modified: Jul. 30, 2025
-
7.8
HIGHCVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could u... Read more
Affected Products : linux_kernel enterprise_linux fedora enterprise_linux_server_aus enterprise_linux_server_tus h410c_firmware enterprise_linux_eus h300s_firmware h500s_firmware h700s_firmware +29 more products- Actively Exploited
- EPSS Score: %84.35
- Published: Mar. 10, 2022
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2022-24990
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.... Read more
- Actively Exploited
- EPSS Score: %94.40
- Published: Feb. 07, 2023
- Modified: Jul. 30, 2025