Latest CVE Feed
-
6.7
MEDIUMCVE-2025-21199
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-6378
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user ... Read more
Affected Products : responsive_food_and_drink_menu- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2019-16869
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.... Read more
Affected Products : netty ubuntu_linux enterprise_linux debian_linux jboss_enterprise_application_platform netty- Published: Sep. 26, 2019
- Modified: Jul. 07, 2025
-
8.1
HIGHCVE-2024-48597
Online Clinic Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /success/editp.php?action=edit.... Read more
Affected Products : online_clinic_management_system- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
7.3
HIGHCVE-2024-50986
An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.... Read more
Affected Products : clementine- Published: Nov. 15, 2024
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2024-51091
Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package... Read more
Affected Products : seajs- Published: Mar. 03, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-5125
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulnerability allows attackers to embed malicious JavaScript ... Read more
- Published: Nov. 14, 2024
- Modified: Jul. 07, 2025
-
8.4
HIGHCVE-2024-51459
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.... Read more
- Published: Mar. 19, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2024-46450
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.... Read more
- Published: Jan. 16, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-40503
An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.... Read more
- Published: Jul. 16, 2024
- Modified: Jul. 07, 2025
-
6.5
MEDIUMCVE-2024-51477
IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.... Read more
- Published: Mar. 29, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
8.0
HIGHCVE-2024-48192
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root... Read more
- Published: Oct. 17, 2024
- Modified: Jul. 07, 2025
-
6.8
MEDIUMCVE-2024-40412
Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.... Read more
- Published: Jul. 10, 2024
- Modified: Jul. 07, 2025
-
10.0
CRITICALCVE-2024-51568
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.... Read more
Affected Products : cyberpanel- Published: Oct. 29, 2024
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2024-50983
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name sect... Read more
Affected Products : flightpath- Published: Nov. 15, 2024
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2024-40515
An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.... Read more
- Published: Jul. 16, 2024
- Modified: Jul. 07, 2025
-
7.5
HIGHCVE-2024-33365
Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.... Read more
- Published: Jul. 29, 2024
- Modified: Jul. 07, 2025
-
4.8
MEDIUMCVE-2024-6165
The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo... Read more
Affected Products : wanotifier- Published: Jul. 31, 2024
- Modified: Jul. 07, 2025
-
5.8
MEDIUMCVE-2024-29030
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.... Read more
Affected Products : memos- Published: Apr. 19, 2024
- Modified: Jul. 07, 2025
-
5.3
MEDIUMCVE-2025-5813
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it po... Read more
Affected Products : amazon_products_to_woocommerce- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization