Latest CVE Feed
-
9.8
CRITICALCVE-2025-8853
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-8841
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads ... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-8842
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-8844
A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has b... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2025-8864
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-8866
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addre... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2012-10040
Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploi... Read more
Affected Products : openfiler- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-20234
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scann... Read more
- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-49591
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain a... Read more
Affected Products : cryptpad- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-20260
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability... Read more
Affected Products : clamav- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-49590
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before ... Read more
Affected Products : cryptpad- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-5071
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authentica... Read more
- Published: Jun. 19, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-1766
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24.... Read more
Affected Products : eventin- Published: Mar. 20, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2025-2109
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to mak... Read more
Affected Products : wp_compress- Published: Mar. 25, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Server-Side Request Forgery
-
8.8
HIGHCVE-2025-2110
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.1... Read more
Affected Products : wp_compress- Published: Mar. 26, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-26964
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20.... Read more
Affected Products : eventin- Published: Feb. 25, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-37507
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.... Read more
Affected Products : eventin- Published: Jul. 21, 2024
- Modified: Aug. 11, 2025
-
5.9
MEDIUMCVE-2024-39648
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.... Read more
Affected Products : eventin- Published: Aug. 01, 2024
- Modified: Aug. 11, 2025
-
6.1
MEDIUMCVE-2022-20634
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP r... Read more
Affected Products : enterprise_chat_and_email- Published: Nov. 15, 2024
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2022-20871
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate priv... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 11, 2025