Latest CVE Feed
-
7.8
HIGHCVE-2025-9175
A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit is public... Read more
Affected Products : shc- Published: Aug. 19, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-50901
JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.... Read more
Affected Products : jeewms- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-50904
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.... Read more
Affected Products : my-site- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-55444
A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code executi... Read more
Affected Products : online_artwork_and_fine_arts_project- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-57520
A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary J... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-57085
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-53495
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.... Read more
Affected Products : my-site- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-57152
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class... Read more
Affected Products : my-site- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-9263
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to... Read more
Affected Products : xxl-job- Published: Aug. 20, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-9264
A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument I... Read more
Affected Products : xxl-job- Published: Aug. 21, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-52194
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, l... Read more
Affected Products : libsndfile- Published: Aug. 21, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.... Read more
Affected Products : enterprise_linux openshift_container_platform libxml2 grub2 libssh international_components_for_unicode- Published: Jun. 12, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-50518
A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library. This issue occurs due to improper handling of memory after the freeing of a PDU object, leading to potential memory corruption or the possi... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-47184
An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a craf... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Sep. 11, 2025
- Vuln Type: XML External Entity
-
5.1
MEDIUMCVE-2025-10255
A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment Handler. Executing manipulation can lead to cross site scripting. The atta... Read more
Affected Products :- Published: Sep. 11, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-9000
A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on... Read more
Affected Products : control_center_gx_v2- Published: Aug. 15, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-9001
A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HTTPGet of the file /Applications/Steal/main.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stack-... Read more
Affected Products : lemonos- Published: Aug. 15, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9002
A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Account leads to sql injection. It is possible to initiate the attack remotely. The exploit has be... Read more
Affected Products : dormitory-management-php- Published: Aug. 15, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-9016
A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to... Read more
Affected Products : control_center_gx_v2- Published: Aug. 15, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-9019
A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity o... Read more
Affected Products : tcpreplay- Published: Aug. 15, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption