Latest CVE Feed
-
4.3
MEDIUMCVE-2025-54251
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited un... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: XML External Entity
-
4.9
MEDIUMCVE-2025-54250
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and ... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-54248
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and g... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-54249
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-54247
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and g... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-54246
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gai... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-7635
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.... Read more
Affected Products : gigacenter_ont- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
8.5
HIGHCVE-2025-54084
OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full ... Read more
Affected Products : gigacenter_ont- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-54083
Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin access to the web interface.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE.... Read more
Affected Products : gigacenter_ont- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Information Disclosure
-
7.0
HIGHCVE-2025-53914
Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.... Read more
Affected Products : gigacenter_ont- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-53913
Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844G, 844GE, 854GE, 812G, 813G, 818G.... Read more
Affected Products : gigacenter_ont- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-50989
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escapin... Read more
Affected Products : opnsense- Published: Aug. 27, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-4009
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup netw... Read more
Affected Products :- Published: May. 28, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-54252
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypass... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-9176
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local ac... Read more
Affected Products : shc- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9173
A weakness has been identified in Emlog Pro up to 2.5.18. This issue affects some unknown processing of the file /admin/media.php?action=upload&sid=0. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched ... Read more
Affected Products : emlog- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-57819
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipul... Read more
Affected Products : freepbx- Actively Exploited
- Published: Aug. 28, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-9287
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.... Read more
Affected Products : cipher-base- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-5086
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.... Read more
Affected Products : delmia_apriso- Actively Exploited
- Published: Jun. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-9288
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.... Read more
Affected Products : sha.js- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection