Latest CVE Feed
-
7.5
HIGHCVE-2025-54525
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
9.9
CRITICALCVE-2025-42957
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability eff... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-30184
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-30507
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-30515
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-30183
CyberData 011209 Intercom does not properly store or protect web server admin credentials.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
4.2
MEDIUMCVE-2025-55013
The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value returned by the se... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-1125
When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows. A maliciouly crafted file... Read more
Affected Products : grub2- Published: Mar. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-0689
When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always ... Read more
Affected Products : grub2- Published: Mar. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-54987
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 b... Read more
Affected Products : apex_one- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-48067
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has ... Read more
Affected Products : octoprint- Published: Jun. 10, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-48879
OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The... Read more
Affected Products : octoprint- Published: Jun. 10, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-5982
An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.... Read more
Affected Products : gitlab- Published: Jun. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
2.5
LOWCVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow atta... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2021-24211
The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.... Read more
- Published: Apr. 05, 2021
- Modified: Aug. 12, 2025
-
5.5
MEDIUMCVE-2025-6196
A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected ... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-27127
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All vers... Read more
Affected Products : tia_project-server- Published: Jul. 08, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2024-54015
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) (All versions >= V8.80 < V... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
7.0
HIGHCVE-2024-53648
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.90), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versio... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2024-52051
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),... Read more
Affected Products : simatic_wincc- Published: Dec. 10, 2024
- Modified: Aug. 12, 2025