Latest CVE Feed
-
6.8
MEDIUMCVE-2025-0140
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit ... Read more
Affected Products : globalprotect_app- Published: Jul. 09, 2025
- Modified: Jul. 30, 2025
-
10.0
CRITICALCVE-2025-0982
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will ... Read more
Affected Products : application_integration- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-22992
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL comma... Read more
Affected Products : emoncms- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-0896
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.... Read more
Affected Products : orthanc- Published: Feb. 13, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-0838
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass... Read more
- Published: Feb. 21, 2025
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2024-37183
Plain text credentials and session ID can be captured with a network sniffer.... Read more
- Published: Jun. 20, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8249
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s3.php. The manipulation of the argument credits leads to sql injection. The ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
8.7
HIGHCVE-2024-32943
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.... Read more
- Published: Jun. 20, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8250
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s4.php. The manipulation of the argument credits leads to sql injection. It is possible to la... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8251
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s4.php. The manipulation of the argument ID leads to sql injection. T... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8269
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_s1.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8270
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s2.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8271
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. The manipulation of the argument ID leads to sql injection. The attack can be ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8272
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/update_fst.php. The manipulation of the argument credits leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8273
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s8.php. The manipulation of the argument credits leads to sql injection. It is possible to launch th... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.9
CRITICALCVE-2025-1041
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.... Read more
Affected Products : call_management_system- Published: Jun. 10, 2025
- Modified: Jul. 30, 2025
-
8.7
HIGHCVE-2024-35246
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.... Read more
- Published: Jun. 20, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2024-5980
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz p... Read more
Affected Products : pytorch_lightning- Published: Jun. 27, 2024
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2024-6038
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword an... Read more
Affected Products : chuanhuchatgpt- Published: Jun. 27, 2024
- Modified: Jul. 30, 2025
-
4.4
MEDIUMCVE-2023-20004
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on ... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 30, 2025