Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.0

    MEDIUM
    CVE-2025-20119

    A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administra... Read more

    • Published: Feb. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Race Condition
  • 4.4

    MEDIUM
    CVE-2025-20118

    A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administra... Read more

    • Published: Feb. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Information Disclosure
  • 9.8

    CRITICAL
    CVE-2025-8254

    A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view_parcel.php. The manipulation of the argument ID leads to sql injection. The attack can be ini... Read more

    Affected Products : courier_management_system
    • Published: Jul. 28, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Injection
  • 6.7

    MEDIUM
    CVE-2025-20117

    A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administ... Read more

    • Published: Feb. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Authentication
  • 4.8

    MEDIUM
    CVE-2025-20116

    A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability i... Read more

    • Published: Feb. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.8

    HIGH
    CVE-2025-0889

    Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation ... Read more

    Affected Products : privilege_management_for_windows
    • Published: Feb. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Authorization
  • 5.5

    MEDIUM
    CVE-2025-21106

    Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.... Read more

    Affected Products : recoverpoint_for_virtual_machines
    • Published: Feb. 20, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Misconfiguration
  • 9.8

    CRITICAL
    CVE-2025-8261

    A vulnerability was found in Vaelsys 4.1.0 and classified as critical. This issue affects some unknown processing of the file /grid/vgrid_server.php of the component User Creation Handler. The manipulation leads to improper authorization. The attack may b... Read more

    Affected Products : vaelsys
    • Published: Jul. 28, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Authorization
  • 7.8

    HIGH
    CVE-2025-21105

    Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action pe... Read more

    Affected Products : recoverpoint_for_virtual_machines
    • Published: Feb. 20, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2025-8260

    A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak ha... Read more

    Affected Products : vaelsys
    • Published: Jul. 28, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Cryptography
  • 9.8

    CRITICAL
    CVE-2025-8259

    A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection. It is possible to... Read more

    Affected Products : vaelsys
    • Published: Jul. 28, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-8168

    A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function websAspInit of the file /goform/formSetWanPPPoE. The manipulation of the argument curTime leads to buffer overflow. The attack may be l... Read more

    Affected Products : dir-513_firmware dir-513
    • Published: Jul. 25, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-8169

    A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPcallback of the file /goform/formSetWanPPTPpath of the component HTTP POST Request Handler. The manipulation of the argument curTime lead... Read more

    Affected Products : dir-513_firmware dir-513
    • Published: Jul. 25, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-8184

    A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stac... Read more

    Affected Products : dir-513_firmware dir-513
    • Published: Jul. 26, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Memory Corruption
  • 6.3

    MEDIUM
    CVE-2020-3539

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit ... Read more

    • Published: Nov. 18, 2024
    • Modified: Jul. 31, 2025
  • 7.5

    HIGH
    CVE-2020-3548

    A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resul... Read more

    • Published: Nov. 18, 2024
    • Modified: Jul. 31, 2025
  • 8.7

    HIGH
    CVE-2025-49484

    A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.... Read more

    Affected Products : js_jobs
    • Published: Jul. 18, 2025
    • Modified: Jul. 31, 2025
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2017-6744

    The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to rel... Read more

    Affected Products : ios
    • Actively Exploited
    • EPSS Score: %12.16
    • Published: Jul. 17, 2017
    • Modified: Jul. 31, 2025
  • 9.0

    HIGH
    CVE-2017-6743

    The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to rel... Read more

    Affected Products : ios_xe ios
    • Actively Exploited
    • EPSS Score: %18.10
    • Published: Jul. 17, 2017
    • Modified: Jul. 31, 2025
  • 9.0

    HIGH
    CVE-2017-6742

    A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected... Read more

    Affected Products : ios_xe ios
    • Actively Exploited
    • EPSS Score: %3.60
    • Published: Jul. 17, 2017
    • Modified: Jul. 31, 2025
Showing 20 of 291782 Results