Latest CVE Feed
-
6.7
MEDIUMCVE-2025-20982
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : android- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-21001
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.... Read more
Affected Products : android- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-27446
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-... Read more
Affected Products : apisix- Published: Jul. 06, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-6675
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 ... Read more
Affected Products : miniorange_2fa- Published: Jun. 26, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2024-53679
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be tricked in to clicking a... Read more
Affected Products : vcl- Published: Mar. 25, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-53678
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned b... Read more
Affected Products : vcl- Published: Mar. 25, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-27165
Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-27367
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-49784
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server fi... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2024-49783
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2024-12580
A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filter... Read more
Affected Products : librechat- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2023-43039
IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-1112
IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.... Read more
- Published: Jul. 09, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-12433
A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication wit... Read more
Affected Products : ragflow- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-27369
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points used for the administration of OpenPages. An authenticated user is able to ob... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-12332
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient prepar... Read more
Affected Products : wpschoolpress- Published: Jan. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-12070
A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sen... Read more
Affected Products : large_language_and_vision_assistant- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Denial of Service
-
7.6
HIGHCVE-2024-11824
A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to ... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-47993
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2022_23h2 windows_server_23h2 windows_11_24h2 windows_server_2025- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-47991
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_11_23h2 windows_server_2022_23h2 +3 more products- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption