Latest CVE Feed
-
7.5
HIGHCVE-2025-53179
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.... Read more
Affected Products : harmonyos- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-53180
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.... Read more
Affected Products : harmonyos- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-44905
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.... Read more
Affected Products : pg- Published: Jun. 12, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-4799
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, ... Read more
Affected Products : wp-downloadmanager- Published: Jun. 11, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2023-48978
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.... Read more
Affected Products : itm_web_terminal- Published: Jun. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2023-50450
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.... Read more
- Published: Jun. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-34031
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read... Read more
Affected Products : jmol- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-34032
A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing... Read more
Affected Products : jmol- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-34033
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level p... Read more
Affected Products : blue_angel_software_suite- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34034
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts all... Read more
Affected Products : blue_angel_software_suite- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-34035
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject a... Read more
Affected Products : esr300_firmware esr300 esr350_firmware esr350 esr600_firmware esr600 esr900_firmware esr900 esr1200_firmware esr1200 +4 more products- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-34036
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the ... Read more
Affected Products : td-2104ts-cl td-2108ts-hp td-2104ts-cl_firmware td-2108ts-hp_firmware td-2108ts-cl_firmware td-2108ts-cl td-2108ts-cl-a_firmware td-2108ts-cl-a td-2116ts-cl_firmware td-2116ts-cl +50 more products- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-6534
A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of the component File Han... Read more
Affected Products : novel-plus- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-6535
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml of the component User Management M... Read more
Affected Products : novel-plus- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2021-41691
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.... Read more
Affected Products : opensis- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-44531
An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-37743
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.... Read more
Affected Products : knowledgegpt- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-45332
vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.... Read more
Affected Products : c-ray- Published: Jun. 25, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-45333
berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.... Read more
Affected Products : abc- Published: Jun. 25, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-51574
Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower. Authentication is not... Read more
Affected Products : viewpower- Published: May. 03, 2024
- Modified: Jul. 09, 2025