Latest CVE Feed
-
5.6
MEDIUMCVE-2025-7396
In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assem... Read more
Affected Products : wolfssl- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
-
7.5
HIGHCVE-2025-27210
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.... Read more
- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-7801
A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /crm/module/HNDCBas_customPrmSearchDtl.jsp. The manipulation of the argument cstid leads to sql injection... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-38350
In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their classes' dequeue handler on an enqueue operation. This may unexpectedly empt... Read more
Affected Products : linux_kernel- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-7865
A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of the file src/main/java/com/jeesite/common/codec/EncodeUtils.java of the component XSS Filter. The manipul... Read more
Affected Products : jeesite- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-7889
A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to impr... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-46383
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-7903
A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers.... Read more
Affected Products : ruoyi- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
7.0
HIGHCVE-2025-7394
In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random num... Read more
Affected Products : wolfssl- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
7.8
HIGHCVE-2025-41459
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic ... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
-
5.3
MEDIUMCVE-2025-6721
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthent... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-4129
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.05.2025.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-7669
The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the 'avishi-wp-paypal-payment-button/index.php' page. T... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-7798
A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System up to 8.2. This affects an unknown part of the file /admin/system/structure/getdirectorydata/web/baseinfo/companyMana... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-1469
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 11.03.2025.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
-
4.8
MEDIUMCVE-2025-41681
A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.... Read more
Affected Products : mbnet.mini_firmware- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-7916
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.... Read more
Affected Products : winmatrix3- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-7906
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java. The manipulation of the argume... Read more
Affected Products : ruoyi- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
8.6
HIGH- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
6.4
MEDIUMCVE-2025-7658
The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temphc-start' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user suppl... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting