Latest CVE Feed
-
5.3
MEDIUMCVE-2024-55599
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all ... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-7326
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor supp... Read more
Affected Products : asp.net_core- Published: Jul. 08, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
8.3
HIGHCVE-2025-54075
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-53645
Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthenticated ... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-53640
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could... Read more
Affected Products : indico- Published: Jul. 14, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
7.7
HIGHCVE-2025-23083
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be g... Read more
Affected Products : node.js- Published: Jan. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2017-3893
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.... Read more
Affected Products : qnx_software_development_platform- EPSS Score: %0.20
- Published: Nov. 14, 2017
- Modified: Jul. 22, 2025
-
7.2
HIGHCVE-2025-20130
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2025-20126
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affecte... Read more
- Published: Jan. 08, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-20259
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on f... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-20273
A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management inte... Read more
Affected Products : unified_intelligent_contact_management_enterprise- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-7863
A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function redirectUrl of the file src/main/java/com/jeesite/common/web/http/ServletUtils.java. The manipulation of the argument url lead... Read more
Affected Products : jeesite- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.1
MEDIUMCVE-2025-7803
A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classified as problematic. This affects the function validToken of the file /wx.php. The manipulation of the argument echostr leads to cross sit... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-7783
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.... Read more
Affected Products : form-data- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2025-53923
Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including pro-2.5.17 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. Due to lack of sanitization it is... Read more
Affected Products : emlog- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-53892
Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.1... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-2699
A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting. T... Read more
- Published: Mar. 24, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2023-45811
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `Li... Read more
Affected Products : synchrony- EPSS Score: %0.13
- Published: Oct. 17, 2023
- Modified: Jul. 22, 2025
-
4.3
MEDIUMCVE-2025-20114
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-suppli... Read more
- Published: May. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization