Latest CVE Feed
-
8.8
HIGHCVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, ... Read more
- Actively Exploited
- Published: Aug. 08, 2025
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-55591
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-55590
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-55589
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2025-55588
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2025-55587
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2025-55586
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-55585
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
5.3
MEDIUMCVE-2025-55584
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
-
6.1
MEDIUMCVE-2024-26484
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this ... Read more
Affected Products : kirby- Published: Feb. 22, 2024
- Modified: Aug. 21, 2025
-
7.1
HIGHCVE-2024-26482
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization... Read more
Affected Products : kirby- Published: Feb. 22, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-9013
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initia... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
-
0.0
NACVE-2023-52656
In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.... Read more
Affected Products : linux_kernel- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
10.0
CRITICALCVE-2024-32741
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack... Read more
- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-25005
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.... Read more
- Published: Aug. 12, 2025
- Modified: Aug. 21, 2025
-
5.3
MEDIUMCVE-2024-11176
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Aug. 21, 2025
-
9.3
CRITICALCVE-2025-48757
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual custo... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Aug. 21, 2025
-
6.1
MEDIUMCVE-2024-34449
Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.... Read more
Affected Products : vditor- Published: May. 03, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-47712
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, l... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 21, 2025
-
3.3
LOWCVE-2025-6199
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 21, 2025