Latest CVE Feed
-
6.5
MEDIUMCVE-2025-47712
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, l... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 21, 2025
-
3.3
LOWCVE-2025-6199
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 21, 2025
-
8.2
HIGHCVE-2025-36016
IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof th... Read more
Affected Products : process_mining- Published: Jun. 21, 2025
- Modified: Aug. 21, 2025
-
8.1
HIGHCVE-2025-5318
A flaw was found in the libssh library. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which... Read more
- Published: Jun. 24, 2025
- Modified: Aug. 21, 2025
-
5.5
MEDIUMCVE-2025-29478
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.... Read more
Affected Products : fluent_bit- Published: Apr. 07, 2025
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6184
A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command inj... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6186
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of the argument ad_log_name leads to os command injection. It is possible... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6187
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack can be ini... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
7.2
HIGHCVE-2024-6269
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function get_ip.addr_details of the file /view/vpn/autovpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the ar... Read more
- Published: Jun. 23, 2024
- Modified: Aug. 21, 2025
-
8.5
HIGHCVE-2024-39567
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This... Read more
- Published: Jul. 09, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3738
A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is p... Read more
- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3739
A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of the argument file leads to os command injection. The attack can be initiate... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3740
A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file /adminPage/conf/reload. The manipulation of the argument nginxExe leads to deserialization. The attack ma... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
6.1
MEDIUMCVE-2024-30953
A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link Name parameter of Menu Editor module.... Read more
Affected Products : htmly- Published: Apr. 17, 2024
- Modified: Aug. 21, 2025
-
6.1
MEDIUMCVE-2024-27306
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) ... Read more
- Published: Apr. 18, 2024
- Modified: Aug. 21, 2025
-
8.4
HIGHCVE-2024-32462
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, ... Read more
- Published: Apr. 18, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-31011
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.... Read more
Affected Products : beescms- Published: Apr. 03, 2024
- Modified: Aug. 21, 2025
-
7.2
HIGHCVE-2025-2773
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication ... Read more
Affected Products : router_firmware- Published: Apr. 23, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-2772
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Auth... Read more
Affected Products : router_firmware- Published: Apr. 23, 2025
- Modified: Aug. 21, 2025
-
7.1
HIGHCVE-2025-8909
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.... Read more
Affected Products : organization_portal_system- Published: Aug. 13, 2025
- Modified: Aug. 21, 2025