Latest CVE Feed
-
6.5
MEDIUMCVE-2025-32430
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabil... Read more
Affected Products : xwiki- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-8244
The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2024-58261
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.... Read more
Affected Products : sequoia-openpgp- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-28172
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to t... Read more
- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-52358
A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters whi... Read more
- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-42645
An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS).... Read more
Affected Products : flashmq- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-42644
FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0.... Read more
Affected Products : flashmq- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-28171
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.... Read more
- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-44137
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion o... Read more
Affected Products : tileserver_php- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-44136
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript co... Read more
Affected Products : tileserver_php- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-28170
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.... Read more
- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2020-25078
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.... Read more
Affected Products : dcs-2530l_firmware dcs-2670l_firmware dcs-2530l dcs-2670l dcs-4603_firmware dcs-4603 dcs-4622_firmware dcs-4622 dcs-4701e_firmware dcs-4701e +8 more products- Actively Exploited
- EPSS Score: %94.20
- Published: Sep. 02, 2020
- Modified: Aug. 06, 2025
-
9.0
HIGHCVE-2020-25079
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.... Read more
Affected Products : dcs-2530l_firmware dcs-2670l_firmware dcs-2530l dcs-2670l dcs-4603_firmware dcs-4603 dcs-4622_firmware dcs-4622 dcs-4701e_firmware dcs-4701e +8 more products- Actively Exploited
- EPSS Score: %45.97
- Published: Sep. 02, 2020
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2022-40799
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.... Read more
- Actively Exploited
- EPSS Score: %73.08
- Published: Nov. 29, 2022
- Modified: Aug. 06, 2025
-
4.8
MEDIUMCVE-2025-8571
Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection ... Read more
- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.0
MEDIUMCVE-2025-54869
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. In versions 2.6.2 and below, any application that uses FPDI to process user-supplied PDF files is at risk, causing a Denial ... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-53534
RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-54594
react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for ... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Supply Chain
-
8.7
HIGHCVE-2025-54872
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shar... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-54613
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025