Latest CVE Feed
-
8.5
HIGHCVE-2025-2285
A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary co... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2025-2287
A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary co... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-2288
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat acto... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-2286
A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary co... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-2293
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat acto... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-2829
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat acto... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-3286
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor ... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-3285
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor ... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-3287
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute ar... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-3288
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor ... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-3289
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute ar... Read more
Affected Products : arena- Published: Apr. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-28766
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-28770
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-28771
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-27444
langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute__, __bases__, __mro_... Read more
- Published: Feb. 26, 2024
- Modified: Jul. 14, 2025
-
7.2
HIGHCVE-2024-25051
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.... Read more
- Published: Apr. 02, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
5.9
MEDIUMCVE-2024-23945
Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilit... Read more
- Published: Dec. 23, 2024
- Modified: Jul. 14, 2025
-
9.8
CRITICALCVE-2024-22330
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.... Read more
Affected Products : security_verify_governance- Published: Jun. 06, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-2221
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwri... Read more
Affected Products : qdrant- Published: Apr. 10, 2024
- Modified: Jul. 14, 2025
-
8.1
HIGHCVE-2024-12880
A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants, they can manipu... Read more
Affected Products : ragflow- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization