Latest CVE Feed
-
7.5
HIGHCVE-2025-1948
In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to alloca... Read more
Affected Products : jetty- Published: May. 08, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-39753
An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system... Read more
Affected Products : apex_one- Published: Oct. 22, 2024
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2024-48904
An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.... Read more
Affected Products : cloud_edge- Published: Oct. 22, 2024
- Modified: Jul. 31, 2025
-
7.1
HIGHCVE-2025-5791
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-41183
Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.... Read more
Affected Products : vpn- Published: Oct. 22, 2024
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-4447
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.... Read more
Affected Products : openj9- Published: May. 09, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token.... Read more
Affected Products : open_vsx- Published: Jun. 27, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-12704
A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a thread and retrieves the result via the get_response_gen m... Read more
Affected Products : llamaindex- Published: Mar. 20, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-1750
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on t... Read more
Affected Products : llamaindex- Published: Jun. 02, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-20396
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handler... Read more
Affected Products : webex_teams- Published: Jul. 17, 2024
- Modified: Jul. 31, 2025
-
7.8
HIGHCVE-2024-48903
An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the t... Read more
- Published: Oct. 22, 2024
- Modified: Jul. 31, 2025
-
7.3
HIGHCVE-2024-20395
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend service... Read more
Affected Products : webex_teams- Published: Jul. 17, 2024
- Modified: Jul. 31, 2025
-
6.5
MEDIUMCVE-2025-29770
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to support structured output (a.k.a. guided decoding). Outlines provides an optional cache for its compiled gram... Read more
Affected Products : vllm- Published: Mar. 19, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-2324
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, fr... Read more
Affected Products : moveit_transfer- Published: Mar. 19, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2022-20663
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.... Read more
Affected Products : secure_network_analytics- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
6.5
MEDIUMCVE-2025-20190
A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient... Read more
Affected Products : ios_xe catalyst_9800-40 catalyst_9800-80 catalyst_9800-l catalyst_9105axi catalyst_9115axe catalyst_9115axi catalyst_9117axi catalyst_9120axe catalyst_9120axi +7 more products- Published: May. 07, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-10707
gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary... Read more
Affected Products : chuanhuchatgpt- Published: Mar. 20, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Path Traversal
-
7.4
HIGHCVE-2022-20814
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of valida... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
7.4
HIGHCVE-2022-20853
A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to in... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025
-
4.3
MEDIUMCVE-2022-20939
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to inadequate protection of sensitive ... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 31, 2025