Latest CVE Feed
-
8.1
HIGHCVE-2025-6505
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client ... Read more
Affected Products :- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2025-6504
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a wh... Read more
Affected Products :- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-54769
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execu... Read more
Affected Products : lpar2rrd- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-54768
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to download logs from the appliance configuration, exposing sensitive informa... Read more
Affected Products : lpar2rrd- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-54767
An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.... Read more
Affected Products : lpar2rrd- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-54766
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to export the appliance configuration, exposing sensitive information.... Read more
Affected Products :- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-54765
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to import the appliance configuration, allowing an attacker to control the co... Read more
Affected Products :- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2014-125116
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing to the applicatio... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2014-125114
A stack-based buffer overflow vulnerability exists in i-Ftp version 2.20 due to improper handling of the Time attribute within Schedule.xml. By placing a specially crafted Schedule.xml file in the i-Ftp application directory, a remote attacker can trigger... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-8097
The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter in the woodmart_update_cart_item function. This makes it possible for unau... Read more
Affected Products : woodmart- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-34139
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topo... Read more
Affected Products : managed_cloud- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-8103
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for u... Read more
Affected Products : wpematico_rss_feed_fetcher- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.1
CRITICALCVE-2025-54416
tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Ac... Read more
Affected Products : branch-names- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-8175
A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference.... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-50184
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that list... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-54366
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical deserialization vulnerability in the /conversation/ajax endpoint that allows authenticated users ... Read more
Affected Products : freescout- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-54412
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide the execution of untrusted operator methods. This can then... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-54414
Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources from scraper bots. In versions 1.21.2 and below, attackers can craft malicious pass-challenge pages that cau... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2025-38448
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix race condition in TTY wakeup A race condition occurs when gs_start_io() calls either gs_start_rx() or gs_start_tx(), as those functions briefly drop the port_... Read more
Affected Products : linux_kernel- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Race Condition
-
5.3
MEDIUMCVE-2025-8176
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. ... Read more
Affected Products : libtiff- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption