Latest CVE Feed
-
5.7
MEDIUMCVE-2025-43486
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the lat... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2025-43485
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the lat... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
6.0
MEDIUMCVE-2025-43484
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issu... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-43483
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
7.3
HIGHCVE-2025-43022
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-43021
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
5.7
MEDIUMCVE-2025-43020
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-54140
pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded file, an attacker ... Read more
Affected Products : pyload- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2025-53703
DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
8.7
HIGHCVE-2025-48733
DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This could allow an attacker to repeatedly reboot the device.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-41425
DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to prevent legitimate users from accessing the web interface.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-51475
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-51472
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, whi... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-51458
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.edit... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-51459
File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hu... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
6.6
MEDIUMCVE-2025-51481
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypa... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-7371
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-51865
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-51864
A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-51860
Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container component. An attacker can achieve arbitrary client-side script execution by crafting an AI Character with SVG XSS payloads in either descr... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting