Latest CVE Feed
-
8.6
HIGHCVE-2024-37358
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version... Read more
- Published: Feb. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-7357
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the function soapcgi_main of the file /soap.cgi. The manipulation of the argument service leads to os command injecti... Read more
- Published: Aug. 01, 2024
- Modified: Jul. 16, 2025
-
9.8
CRITICALCVE-2024-46946
langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9b... Read more
- Published: Sep. 19, 2024
- Modified: Jul. 16, 2025
-
9.8
CRITICALCVE-2024-23106
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HT... Read more
Affected Products : forticlientems- Published: Jan. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-0909
The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on... Read more
- EPSS Score: %0.63
- Published: Feb. 03, 2024
- Modified: Jul. 16, 2025
-
7.5
HIGHCVE-2024-46667
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connect... Read more
Affected Products : fortisiem- Published: Jan. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2017-18524
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.... Read more
- EPSS Score: %0.21
- Published: Aug. 20, 2019
- Modified: Jul. 16, 2025
-
9.0
CRITICALCVE-2024-47572
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file... Read more
Affected Products : fortisoar- Published: Jan. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2021-26700
Visual Studio Code npm-script Extension Remote Code Execution Vulnerability... Read more
- EPSS Score: %12.92
- Published: Feb. 25, 2021
- Modified: Jul. 16, 2025
-
10.0
HIGHCVE-2018-8327
A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.... Read more
- EPSS Score: %21.26
- Published: Jul. 11, 2018
- Modified: Jul. 16, 2025
-
7.6
HIGHCVE-2024-33911
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4. ... Read more
Affected Products : school_management- Published: May. 02, 2024
- Modified: Jul. 16, 2025
-
6.5
MEDIUMCVE-2024-49393
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.... Read more
- Published: Nov. 12, 2024
- Modified: Jul. 16, 2025
-
6.5
MEDIUMCVE-2024-56114
Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to su... Read more
Affected Products : canlineapp- Published: Jan. 09, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2022-31764
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fi... Read more
Affected Products : shardingsphere_elasticjob-ui- Published: Feb. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-0730
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of the argument use... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-41743
IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources.... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-41742
IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a d... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2024-45654
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-53526
composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.... Read more
Affected Products : composio- Published: Jan. 08, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-11685
The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. Thi... Read more
Affected Products : kudos_donations- Published: Nov. 28, 2024
- Modified: Jul. 16, 2025