Latest CVE Feed
-
5.6
MEDIUMCVE-2025-7396
In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve25519. It is not needed, or available with; ARM assembly builds, Intel assem... Read more
Affected Products : wolfssl- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
-
7.5
HIGHCVE-2025-27210
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.... Read more
- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-27209
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an a... Read more
Affected Products : node.js- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Denial of Service
-
9.4
CRITICALCVE-2025-29757
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
4.4
MEDIUMCVE-2025-2301
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers.This issue affects Online Exam Registration: before 14.03.2025.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-30192
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS en... Read more
Affected Products : recursor- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-41100
Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device without the access being logged in the application and even if the access permissions have been revoked.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-41678
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.... Read more
Affected Products : mbnet.mini_firmware- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2025-41677
A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.... Read more
Affected Products : mbnet.mini_firmware- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-46382
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-4570
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Ad... Read more
Affected Products : myasus- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2025-50581
MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-50585
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-52163
A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This ca... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
4.0
MEDIUMCVE-2025-54310
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.... Read more
Affected Products : qbittorrent- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-5681
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 23.06.2025.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-6235
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inj... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-6721
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthent... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
9.2
CRITICALCVE-2025-7395
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to properly verify the server certificate's domain name, allowing any certific... Read more
Affected Products : wolfssl- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-7344
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization