Latest CVE Feed
-
4.4
MEDIUMCVE-2023-20093
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. These vulnerabilities are due to improper access controls on ... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 30, 2025
-
8.8
HIGHCVE-2025-8040
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8038
Firefox ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
-
8.1
HIGHCVE-2025-8036
Firefox cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-8035
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-8034
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enoug... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
8.1
HIGHCVE-2025-8029
Firefox executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.... Read more
- Published: Jul. 22, 2025
- Modified: Jul. 30, 2025
-
7.4
HIGHCVE-2024-26153
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requir... Read more
Affected Products : remote_access_server_firmware- Published: Jan. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2024-21703
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated ... Read more
- Published: Nov. 27, 2024
- Modified: Jul. 30, 2025
-
6.1
MEDIUMCVE-2024-26154
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few differen... Read more
Affected Products : remote_access_server_firmware- Published: Jan. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2022-20793
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulner... Read more
- Published: Nov. 15, 2024
- Modified: Jul. 30, 2025
-
8.6
HIGHCVE-2024-26155
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal. An attacker can access the ETIC RAS web portal and view the HTML code, which is configured to be hidden, thus allowing a connection ... Read more
Affected Products : remote_access_server_firmware- Published: Jan. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2025-54134
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnera... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Denial of Service
-
7.2
HIGHCVE-2025-54128
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application bec... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-54127
HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-26156
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting (XSS) attacks in the method parameter. The ETIC RAS web server uses dynamic pages that gets their input from the client side and ref... Read more
Affected Products : remote_access_server_firmware- Published: Jan. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
HIGHCVE-2021-27084
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability... Read more
- Published: Mar. 11, 2021
- Modified: Jul. 30, 2025
-
8.4
HIGHCVE-2024-6658
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From 7.2.49... Read more
- Published: Sep. 12, 2024
- Modified: Jul. 30, 2025
-
7.8
HIGHCVE-2024-5998
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest versi... Read more
Affected Products : langchain- Published: Sep. 17, 2024
- Modified: Jul. 30, 2025
-
8.4
HIGHCVE-2025-54317
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to remote code execution (RCE).... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Path Traversal