Latest CVE Feed
-
8.0
HIGHCVE-2023-44431
BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exp... Read more
Affected Products : bluez- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2025-47161
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : defender_for_endpoint- Published: May. 15, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-43614
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.... Read more
Affected Products : defender_for_endpoint- Published: Oct. 08, 2024
- Modified: Jul. 08, 2025
-
10.0
HIGHCVE-2012-5864
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.... Read more
- Published: Nov. 23, 2012
- Modified: Jul. 08, 2025
-
10.0
HIGHCVE-2012-5863
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dang... Read more
- Published: Nov. 23, 2012
- Modified: Jul. 08, 2025
-
10.0
HIGHCVE-2012-5862
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access... Read more
- Published: Nov. 23, 2012
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2012-5861
These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the... Read more
- Published: Nov. 23, 2012
- Modified: Jul. 08, 2025
-
5.5
MEDIUMCVE-2024-6986
A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML... Read more
Affected Products : lollms_web_ui- Published: Mar. 20, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-21174
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.... Read more
- Published: Apr. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-24068
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +4 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-24065
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +4 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
4.4
MEDIUMCVE-2024-7058
A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on t... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-8581
A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Travers... Read more
Affected Products : lollms_web_ui- Published: Mar. 20, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
8.0
HIGHCVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required... Read more
Affected Products : bluez- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50190
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to ex... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50189
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50188
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50187
Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50195
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50194
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025