Latest CVE Feed
-
8.4
HIGHCVE-2024-8534
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserv... Read more
- Published: Nov. 12, 2024
- Modified: Jul. 25, 2025
-
6.5
MEDIUMCVE-2024-49823
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
3.7
LOWCVE-2024-41760
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2024-22340
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
2.7
LOWCVE-2024-52905
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.... Read more
- Published: Mar. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-47109
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.... Read more
- Published: Mar. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-1349
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus... Read more
- Published: Jun. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
4.0
MEDIUMCVE-2025-1348
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.... Read more
- Published: Jun. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-54172
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user t... Read more
- Published: Jun. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-54183
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alte... Read more
- Published: Jun. 18, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2025-36050
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.... Read more
- Published: Jun. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2025-33121
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
- Published: Jun. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: XML External Entity
-
9.1
CRITICALCVE-2025-33117
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.... Read more
- Published: Jun. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-58248
nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.... Read more
Affected Products : nopcommerce- Published: Apr. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2024-51978
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IP... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-51977
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.cs... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2014-9192
Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large ... Read more
Affected Products : vtscada- EPSS Score: %1.88
- Published: Dec. 11, 2014
- Modified: Jul. 25, 2025
-
7.8
HIGH- Published: Jul. 12, 2024
- Modified: Jul. 25, 2025
-
8.7
HIGHCVE-2025-6948
An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by inj... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
2.7
LOWCVE-2025-6168
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization