Latest CVE Feed
-
5.9
MEDIUMCVE-2025-44612
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.... Read more
- Published: May. 30, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
7.5
HIGHCVE-2025-44614
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.... Read more
- Published: May. 30, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
9.1
CRITICALCVE-2025-44619
Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.... Read more
- Published: May. 30, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-45784
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis t... Read more
Affected Products : dph-400se_firmware dph-400se dph-400se_firmware dph-400se dph-400s_firmware dph-400s dph-400s_firmware dph-400s- Published: Jun. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cryptography
-
7.2
HIGHCVE-2025-20284
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied i... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-20283
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied i... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
4.1
MEDIUMCVE-2025-20285
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is d... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-7872
A vulnerability was found in Portabilis i-Diario 1.5.0 and classified as problematic. This issue affects some unknown processing of the file /justificativas-de-falta. The manipulation of the argument Justificativa leads to cross site scripting. The attack... Read more
Affected Products : i-diario- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-7871
A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of the argument filter[by_description] leads to cross site scripting. The attack ca... Read more
Affected Products : i-diario- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-7870
A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation of the argument Anexo leads to cross site scripting. It is possi... Read more
Affected Products : i-diario- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-52362
Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specia... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-51869
Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} end... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-51868
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-44654
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network att... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-34511
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server u... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2025-34509
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote at... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-20279
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative crede... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2025-20277
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2025-20276
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credential... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-20275
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device. This vulnerability is due to insecure deserializatio... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration