Latest CVE Feed
-
5.9
MEDIUMCVE-2025-43023
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cryptography
-
5.9
MEDIUMCVE-2022-50237
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2025-26400
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify ... Read more
Affected Products : web_help_desk- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: XML External Entity
-
4.8
MEDIUMCVE-2025-27800
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashb... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-27801
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReferenc... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-29534
An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root privileges. The issue stems from insufficient sanitization of user-suppl... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-1752
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically ... Read more
Affected Products : llamaindex- Published: May. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-1079
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature... Read more
- Published: May. 12, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Path Traversal
-
4.7
MEDIUMCVE-2025-20216
A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper saniti... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
7.9
HIGHCVE-2024-52880
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 0... Read more
Affected Products : kernel- Published: May. 15, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2025-4600
A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The issue ... Read more
Affected Products : application_load_balancer- Published: May. 16, 2025
- Modified: Jul. 29, 2025
-
10.0
CRITICALCVE-2025-20337
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vuln... Read more
- Actively Exploited
- Published: Jul. 16, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-8139
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been classified as critical. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type lea... Read more
- Published: Jul. 25, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-8138
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formOneKeyAccessButton of the component HTTP POST Request Handler. The manipulation of th... Read more
- Published: Jul. 25, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-8137
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the ... Read more
- Published: Jul. 25, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-8140
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formWlanMultipleAP of the component HTTP POST Request Handler. The manipulation of the argument... Read more
- Published: Jul. 25, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Memory Corruption
-
4.6
MEDIUMCVE-2024-29980
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Ma... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jul. 28, 2025
-
4.6
MEDIUMCVE-2024-29979
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix SecureCore™ for Intel Coffee Lake, Phoenix SecureCore™ for Intel Comet Lake, Phoenix SecureCore™ for Intel Ice Lake allows Input Data Ma... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jul. 28, 2025
-
7.5
HIGHCVE-2024-1598
Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.... Read more
- Published: May. 14, 2024
- Modified: Jul. 28, 2025
-
3.3
LOWCVE-2024-12533
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data Manipulation.This issue affects SecureCore Technology 4: from 4.0.1.0 before 4.0.1.1018, from 4.1.0.1 before 4.1.0.573, from 4.2.0.1 be... Read more
Affected Products :- Published: May. 13, 2025
- Modified: Jul. 28, 2025