Latest CVE Feed
-
5.5
MEDIUMCVE-2025-47111
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, ... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-47112
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-46993
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46996
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-47061
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-12284
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.... Read more
- Published: Feb. 20, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-7404
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1... Read more
Affected Products : calibre-web- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-52902
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.... Read more
- Published: Feb. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2025-33112
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2024-8535
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resou... Read more
- Published: Nov. 12, 2024
- Modified: Jul. 25, 2025
-
6.5
MEDIUMCVE-2024-28786
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.... Read more
- Published: Jan. 28, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2024-39750
IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.... Read more
Affected Products : analytics_content_hub- Published: Jan. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2024-35134
IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
Affected Products : analytics_content_hub- Published: Jan. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
9.6
CRITICALCVE-2024-56347
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.... Read more
Affected Products : aix- Published: Mar. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2024-56346
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.... Read more
Affected Products : aix- Published: Mar. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2024-8534
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserv... Read more
- Published: Nov. 12, 2024
- Modified: Jul. 25, 2025
-
6.5
MEDIUMCVE-2024-49823
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
3.7
LOWCVE-2024-41760
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2024-22340
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
2.7
LOWCVE-2024-52905
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.... Read more
- Published: Mar. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure