Latest CVE Feed
-
8.0
HIGHCVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required... Read more
Affected Products : bluez- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50190
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to ex... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50189
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50188
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50187
Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50195
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50194
Trimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50193
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
4.8
MEDIUMCVE-2025-2205
The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanit... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 12, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-1785
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite... Read more
- Published: Mar. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2023-50192
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50191
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2024-11283
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This mak... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11284
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the acco... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11285
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via th... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11286
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the cs_parse_request() function. ... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50196
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
8.1
HIGHCVE-2025-33070
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +8 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-33071
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-0966
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection