Latest CVE Feed
-
6.5
MEDIUMCVE-2018-6542
In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c.... Read more
- EPSS Score: %0.28
- Published: Feb. 02, 2018
- Modified: Jul. 10, 2025
-
5.5
MEDIUMCVE-2025-27736
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows windows_11_23h2 +4 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
6.0
MEDIUMCVE-2025-27735
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows +5 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2024-32231
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.... Read more
Affected Products : stash- Published: Aug. 15, 2024
- Modified: Jul. 10, 2025
-
7.8
HIGHCVE-2025-27733
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_1507 windows windows_server_2012_r2 windows_server_2008_r2 +1 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-45993
Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.... Read more
Affected Products : giflib- Published: Sep. 30, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2024-43346
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wow-Company Modal Window allows Stored XSS.This issue affects Modal Window: from n/a through 6.0.3.... Read more
Affected Products : modal_window- Published: Aug. 18, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2025-26664
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.... Read more
- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2024-45920
A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.... Read more
Affected Products : solvait- Published: Sep. 30, 2024
- Modified: Jul. 10, 2025
-
7.5
HIGHCVE-2024-44860
An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.... Read more
Affected Products : solvait- Published: Sep. 26, 2024
- Modified: Jul. 10, 2025
-
8.1
HIGHCVE-2025-26663
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Apr. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-37097
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service... Read more
Affected Products : insight_remote_support- Published: Jul. 01, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2024-41659
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a c... Read more
Affected Products : memos- Published: Aug. 20, 2024
- Modified: Jul. 10, 2025
-
7.5
HIGHCVE-2025-37098
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.... Read more
Affected Products : insight_remote_support- Published: Jul. 01, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2024-6883
The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthorized plugin settings modification due to a missing capability check on the saveTimezoneString and some other functions in all versions up... Read more
Affected Products : event_espresso- Published: Aug. 21, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2025-37099
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.... Read more
Affected Products : insight_remote_support- Published: Jul. 01, 2025
- Modified: Jul. 10, 2025
-
8.1
HIGHCVE-2024-46097
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another... Read more
Affected Products : testlink- Published: Sep. 27, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2024-5335
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store... Read more
Affected Products : ultimate_store_kit- Published: Aug. 21, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2024-8030
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store... Read more
Affected Products : ultimate_store_kit- Published: Aug. 28, 2024
- Modified: Jul. 10, 2025
-
7.2
HIGHCVE-2022-2440
The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call file... Read more
Affected Products : theme_editor- Published: Aug. 29, 2024
- Modified: Jul. 10, 2025