Latest CVE Feed
-
4.3
MEDIUMCVE-2024-57969
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.... Read more
Affected Products : misp- Published: Feb. 14, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2024-32568
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP 2FA allows Reflected XSS.This issue affects WP 2FA: from n/a through 2.6.2. ... Read more
Affected Products : wp_2fa- Published: Apr. 18, 2024
- Modified: Jul. 09, 2025
-
4.2
MEDIUMCVE-2025-26058
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.... Read more
Affected Products : qloapps- Published: Feb. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-25957
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : xunruicms- Published: Feb. 20, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2024-32488
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.... Read more
- Published: Apr. 15, 2024
- Modified: Jul. 09, 2025
-
9.1
CRITICALCVE-2024-38657
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.... Read more
- Published: Feb. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-42815
In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash o... Read more
- Published: Aug. 19, 2024
- Modified: Jul. 09, 2025
-
5.1
MEDIUMCVE-2025-25772
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.... Read more
Affected Products : jspxcms- Published: Feb. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2024-6448
The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to the error reporting being enabled by default in multiple plugin files. This makes it possible for un... Read more
Affected Products : mollie_payments_for_woocommerce- Published: Aug. 28, 2024
- Modified: Jul. 09, 2025
-
7.4
HIGHCVE-2024-2299
A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers can exploit this vulnerability by uploading malicious HTM... Read more
- Published: May. 14, 2024
- Modified: Jul. 09, 2025
-
9.8
CRITICALCVE-2024-2358
A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifica... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
9.6
CRITICALCVE-2024-2361
A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
9.0
CRITICALCVE-2024-2366
A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises d... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
8.4
HIGHCVE-2024-3126
A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used ... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
8.4
HIGHCVE-2024-3435
A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in ... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
7.5
HIGHCVE-2024-4322
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on th... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
9.8
CRITICALCVE-2024-4326
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by... Read more
- Published: May. 16, 2024
- Modified: Jul. 09, 2025
-
4.0
MEDIUMCVE-2024-4330
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious ... Read more
- Published: May. 30, 2024
- Modified: Jul. 09, 2025
-
7.5
HIGHCVE-2024-2178
A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'ca... Read more
- Published: Jun. 02, 2024
- Modified: Jul. 09, 2025
-
7.8
HIGHCVE-2025-26674
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.... Read more
Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 +2 more products- Published: Apr. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption