Latest CVE Feed
-
9.1
CRITICALCVE-2025-33117
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands.... Read more
- Published: Jun. 19, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
3.5
LOWCVE-2024-58248
nopCommerce before 4.80.0 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.... Read more
Affected Products : nopcommerce- Published: Apr. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2024-51978
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IP... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-51977
An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.cs... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2014-9192
Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large ... Read more
Affected Products : vtscada- Published: Dec. 11, 2014
- Modified: Jul. 25, 2025
-
7.8
HIGH- Published: Jul. 12, 2024
- Modified: Jul. 25, 2025
-
8.7
HIGHCVE-2025-6948
An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by inj... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
2.7
LOWCVE-2025-6168
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2025-4972
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-3396
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API reque... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-53930
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_especie.php` endpoint of the WeGIA application prior to version 3.4... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53929
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cor.php` endpoint of the WeGIA application prior to version 3.4.5. ... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-53938
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-53937
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the `/controle/control.php` endpoint, specifically in the `cargo` parameter, of WeGIA prior to version... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-53936
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to ver... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53935
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `personalizacao_selecao.php` endpoint of the WeGIA application prior to ver... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53934
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint of the WeGIA application prior to version 3.4.5. This v... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53933
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_enfermidade.php` endpoint of the WeGIA application prior to version... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53932
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `cadastro_adotante.php` endpoint of the WeGIA application prior to version ... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-53931
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_raca.php` endpoint of the WeGIA application prior to version 3.4.5.... Read more
Affected Products : wegia- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting