Latest CVE Feed
-
4.0
MEDIUMCVE-2025-53839
DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutraliz... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-29606
py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.... Read more
Affected Products : libp2p- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-7571
A vulnerability classified as critical has been found in UTT HiPER 840G up to 3.1.1-190328. This affects an unknown part of the file /goform/aspApBasicConfigUrcp. The manipulation of the argument Username leads to buffer overflow. It is possible to initia... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-7567
A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be initiated... Read more
Affected Products : shopxo- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-7487
A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The manipulation of the argument portrai... Read more
Affected Products :- Published: Jul. 12, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-7577
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotel... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-7554
A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of the file urlfilter.asp of the component URL Filtering Page. The manipulation of the argument URL address leads to cross site scripting... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-7573
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects the function bs_GetManPwd in the library libblinkapi.so of the file /c... Read more
Affected Products : bl-ac3600_firmware- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-53865
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).... Read more
Affected Products : roundup- Published: Jul. 13, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
HIGHCVE-2025-7574
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web... Read more
Affected Products : bl-ac3600_firmware- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-7488
A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. The manipulation of the argument Nam... Read more
Affected Products :- Published: Jul. 12, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-7012
An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.... Read more
Affected Products :- Published: Jul. 13, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-58258
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.... Read more
Affected Products : sugarcrm- Published: Jul. 13, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Server-Side Request Forgery
-
7.8
HIGHCVE-2025-25180
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU... Read more
Affected Products : ddk- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7451
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7619
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-7620
The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to down... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-7572
A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This vulnerability affects the function bs_GetHostInfo in the library libblinkapi.so of the file /cgi-bin/... Read more
Affected Products : bl-ac3600_firmware- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2025-7380
A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to inject malicious scripts into the folder name field while creating a new shared folder. These scripts are not properly sanitized and wil... Read more
Affected Products : data_master- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.8
MEDIUMCVE-2025-7575
A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the file submit.php. The manipulation leads to path traversal. The attack... Read more
Affected Products :- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal