Latest CVE Feed
-
7.7
HIGHCVE-2024-21548
Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the wi... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Jul. 24, 2025
-
9.8
CRITICALCVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.... Read more
Affected Products : linux_kernel aix infosphere_information_server windows infosphere_information_server_on_cloud- Published: Nov. 16, 2022
- Modified: Jul. 23, 2025
-
8.8
HIGHCVE-2022-3388
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.... Read more
- Published: Nov. 21, 2022
- Modified: Jul. 23, 2025
-
4.4
MEDIUMCVE-2021-39077
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215587.... Read more
- Published: Nov. 03, 2022
- Modified: Jul. 23, 2025
-
6.5
MEDIUMCVE-2024-40585
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2023-33300
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communica... Read more
Affected Products : fortinac- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-7762
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer o... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-7758
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulat... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Memory Corruption
-
8.1
HIGHCVE-2024-8238
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-6851
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFil... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-6829
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control `repo.path` and `... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-6483
A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-10110
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server b... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-6396
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path... Read more
Affected Products : aim- Published: Jul. 12, 2024
- Modified: Jul. 23, 2025
-
7.5
HIGHCVE-2024-8061
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to o... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-45986
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac paramete... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 +6 more products- Published: Jun. 13, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2024-7726
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open JTAG debug port that is exposed on ... Read more
- Published: Dec. 20, 2024
- Modified: Jul. 23, 2025
-
6.8
MEDIUMCVE-2024-12236
A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended s... Read more
Affected Products : vertex_gemini_api- Published: Dec. 10, 2024
- Modified: Jul. 23, 2025
-
7.5
HIGHCVE-2024-11407
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be... Read more
Affected Products : grpc- Published: Nov. 26, 2024
- Modified: Jul. 23, 2025
-
7.5
HIGHCVE-2024-11498
There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will ... Read more
Affected Products : libjxl- Published: Nov. 25, 2024
- Modified: Jul. 23, 2025