Latest CVE Feed
-
5.4
MEDIUMCVE-2025-47001
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-43712
JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value... Read more
Affected Products : jhipster- Published: Jul. 25, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2025-20145
A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets are handled incor... Read more
- Published: Mar. 12, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2025-20144
A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect handling of packets when a sp... Read more
Affected Products : ios_xr ncs_5501-se ncs_5502-se ncs_5508 ncs_5516 ncs_5501 ncs_5502 ncs_540-12z20g-sys-a ncs_540-12z20g-sys-d ncs_540-24z8q2c-sys +29 more products- Published: Mar. 12, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-46059
langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this i... Read more
Affected Products :- Published: Jul. 29, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-8220
A vulnerability classified as critical has been found in Engeman Web up to 12.0.0.1. Affected is an unknown function of the file /Login/RecoveryPass of the component Password Recovery Page. The manipulation of the argument LanguageCombobox as part of Cook... Read more
Affected Products :- Published: Jul. 27, 2025
- Modified: Aug. 03, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-13972
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYSTEM level privileges during a product upgrade.... Read more
Affected Products :- Published: Jul. 17, 2025
- Modified: Aug. 03, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-33014
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information... Read more
- Published: Jul. 18, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-52363
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative... Read more
- Published: Jul. 14, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-53928
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.... Read more
Affected Products : maxkb- Published: Jul. 17, 2025
- Modified: Aug. 02, 2025
-
6.3
MEDIUMCVE-2025-53927
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2... Read more
Affected Products : maxkb- Published: Jul. 17, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-6993
The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corr... Read more
Affected Products : ultimate_wp_mail- Published: Jul. 16, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-30483
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information di... Read more
- Published: Jul. 15, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-7504
The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to injec... Read more
Affected Products : friends- Published: Jul. 12, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-2793
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb... Read more
- Published: Jul. 08, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-2827
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.... Read more
- Published: Jul. 08, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-3630
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to ... Read more
- Published: Jul. 08, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3262
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular expression complexity in the `SETTING_RE` variable with... Read more
Affected Products : transformers- Published: Jul. 07, 2025
- Modified: Aug. 02, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-7078
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been ... Read more
- Published: Jul. 06, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-45809
BerriAI litellm v1.65.4 was discovered to contain a SQL injection vulnerability via the /key/block endpoint.... Read more
Affected Products : litellm- Published: Jul. 03, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Injection