Latest CVE Feed
-
7.2
HIGHCVE-2024-9855
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the compone... Read more
- Published: Oct. 11, 2024
- Modified: Jul. 30, 2025
-
5.1
MEDIUMCVE-2024-9856
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyright l... Read more
- Published: Oct. 11, 2024
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2024-8755
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.... Read more
- Published: Oct. 11, 2024
- Modified: Jul. 30, 2025
-
8.9
HIGHCVE-2024-8912
An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: * Looker (Google Cloud core) was found to be vulnerab... Read more
- Published: Oct. 11, 2024
- Modified: Jul. 30, 2025
-
7.2
HIGHCVE-2024-9903
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possi... Read more
- Published: Oct. 12, 2024
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2025-4948
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart me... Read more
- Published: May. 19, 2025
- Modified: Jul. 30, 2025
-
7.3
HIGHCVE-2025-48797
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a ... Read more
- Published: May. 27, 2025
- Modified: Jul. 30, 2025
-
7.3
HIGHCVE-2025-48796
A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file to trigger arbitrar... Read more
Affected Products : gimp- Published: May. 27, 2025
- Modified: Jul. 30, 2025
-
7.2
HIGHCVE-2024-9904
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted uplo... Read more
- Published: Oct. 13, 2024
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2024-1728
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SS... Read more
Affected Products : gradio- Published: Apr. 10, 2024
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2024-1561
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()`... Read more
Affected Products : gradio- Published: Apr. 16, 2024
- Modified: Jul. 30, 2025
-
5.3
MEDIUMCVE-2024-1681
corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerabili... Read more
- Published: Apr. 19, 2024
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2024-3622
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the... Read more
Affected Products : mirror_registry- Published: Apr. 25, 2024
- Modified: Jul. 30, 2025
-
8.1
HIGHCVE-2024-3623
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registr... Read more
Affected Products : mirror_registry- Published: Apr. 25, 2024
- Modified: Jul. 30, 2025
-
7.3
HIGHCVE-2025-48798
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-... Read more
- Published: May. 27, 2025
- Modified: Jul. 30, 2025
-
6.7
MEDIUMCVE-2024-20306
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an at... Read more
Affected Products : ios_xe- Published: Mar. 27, 2024
- Modified: Jul. 30, 2025
-
8.2
HIGHCVE-2024-21690
This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. This Reflect... Read more
- Published: Aug. 21, 2024
- Modified: Jul. 30, 2025
-
5.6
MEDIUMCVE-2024-20309
A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specif... Read more
Affected Products : ios_xe- Published: Mar. 27, 2024
- Modified: Jul. 30, 2025
-
8.6
HIGHCVE-2024-20311
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to the incorrect handl... Read more
- Published: Mar. 27, 2024
- Modified: Jul. 30, 2025
-
4.3
MEDIUMCVE-2024-21684
There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open re... Read more
Affected Products : bitbucket_data_center- Published: Jul. 24, 2024
- Modified: Jul. 30, 2025