Latest CVE Feed
-
5.9
MEDIUMCVE-2024-20852
Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.... Read more
Affected Products : smartthings- Published: Apr. 02, 2024
- Modified: Jul. 17, 2025
-
9.8
CRITICALCVE-2024-24724
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.... Read more
Affected Products : gibbon- Published: Apr. 03, 2024
- Modified: Jul. 17, 2025
-
6.4
MEDIUMCVE-2024-0873
The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shortcode in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : watu_quiz- Published: Apr. 09, 2024
- Modified: Jul. 17, 2025
-
5.3
MEDIUMCVE-2020-26939
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OA... Read more
- EPSS Score: %2.35
- Published: Nov. 02, 2020
- Modified: Jul. 17, 2025
-
5.9
MEDIUMCVE-2020-15522
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timi... Read more
- EPSS Score: %0.55
- Published: May. 20, 2021
- Modified: Jul. 17, 2025
-
5.4
MEDIUMCVE-2025-4405
The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
- Published: May. 22, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-4419
The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 via the 'path' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to access arbitrar... Read more
- Published: May. 22, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2022-39983
File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.... Read more
Affected Products : rd3- EPSS Score: %0.16
- Published: Feb. 22, 2023
- Modified: Jul. 17, 2025
-
8.8
HIGHCVE-2025-48918
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-48919
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.... Read more
- Published: Jun. 13, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-12063
A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by ... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-52497
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input.... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-49601
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, allowing a possible out-of-bounds read on truncated input. Specifically, an out-of-bounds read in mbedtls_... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-49600
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbed... Read more
- Published: Jul. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cryptography
-
5.4
MEDIUMCVE-2025-27809
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.... Read more
- Published: Mar. 25, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-25724
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that is read with a verbose value of 2. For example, the 100-b... Read more
Affected Products : libarchive- Published: Mar. 02, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service
-
8.2
HIGHCVE-2025-0452
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. Thi... Read more
Affected Products : db-gpt- Published: Mar. 20, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2024-8029
An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, ... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
3.1
LOWCVE-2025-7703
Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-50103
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple ... Read more
- Published: Jul. 15, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service