Latest CVE Feed
-
5.3
MEDIUMCVE-2025-10095
A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certain parameters within the server's database interactions. The vulnerability is isolated to the SMPP server,... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-9872
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-9712
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Misconfiguration
-
2.3
LOWCVE-2025-8448
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network an... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-9111
The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : wpbot- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-8889
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-50586
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).... Read more
Affected Products : studentmanage- Published: Jul. 18, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-50585
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.... Read more
Affected Products : studentmanage- Published: Jul. 18, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-50584
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.... Read more
Affected Products : studentmanage- Published: Jul. 18, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-50582
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.... Read more
Affected Products : studentmanage- Published: Jul. 18, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-50583
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.... Read more
Affected Products : studentmanage- Published: Jul. 18, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-1053
Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption ke... Read more
Affected Products : brocade_sannav- Published: Feb. 14, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2024-7517
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific e... Read more
- Published: Nov. 21, 2024
- Modified: Sep. 09, 2025
-
8.6
HIGHCVE-2024-5461
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or para... Read more
Affected Products : fabric_operating_system- Published: Feb. 15, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2025-56689
One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can by... Read more
Affected Products : one_identity- Published: Sep. 03, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authentication
-
7.0
HIGHCVE-2025-9577
A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking loc... Read more
- Published: Aug. 28, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-49604
For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the WLAN driver defragment function, lack ... Read more
- Published: Jul. 09, 2025
- Modified: Sep. 09, 2025
-
7.0
HIGHCVE-2025-9576
A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached loc... Read more
- Published: Aug. 28, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-55409
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.... Read more
Affected Products : foxcms- Published: Aug. 25, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-53499
Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.... Read more
Affected Products : jeewms- Published: Aug. 22, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection