Latest CVE Feed
-
9.1
CRITICALCVE-2025-50989
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escapin... Read more
Affected Products : opnsense- Published: Aug. 27, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-4009
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup netw... Read more
Affected Products :- Published: May. 28, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-54252
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypass... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-9176
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local ac... Read more
Affected Products : shc- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9173
A weakness has been identified in Emlog Pro up to 2.5.18. This issue affects some unknown processing of the file /admin/media.php?action=upload&sid=0. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched ... Read more
Affected Products : emlog- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-57819
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipul... Read more
Affected Products : freepbx- Actively Exploited
- Published: Aug. 28, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-9287
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.... Read more
Affected Products : cipher-base- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-5086
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.... Read more
Affected Products : delmia_apriso- Actively Exploited
- Published: Jun. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-9288
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.... Read more
Affected Products : sha.js- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-9262
A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The att... Read more
Affected Products : mcp-cli- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9296
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the ... Read more
Affected Products : emlog- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-9300
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be ... Read more
Affected Products : libsixel- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-9308
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this att... Read more
Affected Products : yarn- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-9310
A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vulnerability is an unknown functionality of the file /carRental_war/druid/login.html of the component Druid. Executing manipulation can le... Read more
Affected Products : carrental- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-8916
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS ... Read more
Affected Products : bouncy_castle_for_java- Published: Aug. 13, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-8885
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associate... Read more
Affected Products : bouncy_castle_for_java- Published: Aug. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-49831
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there... Read more
Affected Products : conjur- Published: Jul. 15, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-6436
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: through 20231215.... Read more
Affected Products : web_sablonu_yazilimi- Published: Jan. 02, 2024
- Modified: Sep. 12, 2025
-
6.1
MEDIUMCVE-2025-2488
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox allows Cross-Site Scripting (XSS).This issue affects SambaBox: before 5.1.... Read more
Affected Products : sambabox- Published: May. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2421
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.... Read more
Affected Products : sambabox- Published: May. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection