Latest CVE Feed
-
9.8
CRITICALCVE-2024-53298
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem acce... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-32753
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-6347
A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code of the file /responsive/resblog/blogadmin/admin/pageViewMembers.php. The manipulation leads to cross ... Read more
Affected Products : responsive_blog_site- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6353
A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument keyword leads to cross site scripting. The attac... Read more
Affected Products : responsive_blog_site- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6446
A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /clientdetails/admin/index.php. The manipulation of the argument Username leads to sql inj... Read more
Affected Products : client_details_system- Published: Jun. 21, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6484
A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql ... Read more
Affected Products : online_shopping_store- Published: Jun. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5145
A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects an unknown part of the file /www/cgi-bin/ of the component Query String Handler... Read more
Affected Products :- Published: May. 25, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22952
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.... Read more
Affected Products : memos- Published: Feb. 27, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2024-57240
A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : webviewer- Published: Mar. 03, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-37479
Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1... Read more
Affected Products : element_kit_for_elementor- Published: Jul. 02, 2024
- Modified: Jul. 10, 2025
-
7.5
HIGHCVE-2024-53450
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.... Read more
Affected Products : ragflow- Published: Dec. 09, 2024
- Modified: Jul. 10, 2025
-
9.1
CRITICALCVE-2024-5926
A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service (DoS). This issue is present in all versions of the application. The vulne... Read more
Affected Products : devika- Published: Jun. 30, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2024-38993
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products : jsonic- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2024-39853
adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products : swiper- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2024-39929
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.... Read more
Affected Products : exim- Published: Jul. 04, 2024
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2024-36387
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.... Read more
- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
8.8
HIGHCVE-2024-6353
The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on ... Read more
Affected Products : terawallet- Published: Jul. 12, 2024
- Modified: Jul. 10, 2025
-
6.1
MEDIUMCVE-2024-45031
When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads cou... Read more
Affected Products : syncope- Published: Oct. 24, 2024
- Modified: Jul. 10, 2025
-
9.1
CRITICALCVE-2024-23590
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.... Read more
Affected Products : kylin- Published: Nov. 04, 2024
- Modified: Jul. 10, 2025
-
4.9
MEDIUMCVE-2024-50378
Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive variables were set via airflow CLI, values of those variables appeare... Read more
Affected Products : airflow- Published: Nov. 08, 2024
- Modified: Jul. 10, 2025