Latest CVE Feed
-
6.5
MEDIUMCVE-2024-54169
IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2024-54170
IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consumes excessive CPU cycles.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-54171
IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
- Published: Feb. 06, 2025
- Modified: Jul. 07, 2025
- Vuln Type: XML External Entity
-
6.1
MEDIUMCVE-2024-54957
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their... Read more
Affected Products : nagios_xi- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-54960
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.... Read more
Affected Products : nagios_xi- Published: Feb. 20, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-55160
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.... Read more
Affected Products : gfast- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2021-4457
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.... Read more
Affected Products : zoomsounds- Published: Jun. 25, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-25905
Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.... Read more
Affected Products : cadclick- Published: Jun. 25, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
3.3
LOWCVE-2025-6658
PDF-XChange Editor PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-6659
PDF-XChange Editor PRC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2024-40090
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthenticated attackers to leak memory addresses of uClibc and the stack via sending a GET request to the index page.... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.1
CRITICALCVE-2024-40089
A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to execute arbitrary code by injecting shell commands into the name of the Vilo device.... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
5.3
MEDIUMCVE-2024-40088
A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in the path of any ... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.6
CRITICALCVE-2024-40087
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP service on port 5432 allows remote, unauthenticated attackers to gain administrative access over the router.... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
9.6
CRITICALCVE-2024-40084
A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitrary code via exceptionally long HTTP methods or paths.... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
7.8
HIGHCVE-2025-6660
PDF-XChange Editor GIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to explo... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2025-24988
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2024-48232
An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request fo... Read more
Affected Products : mipjz- Published: Oct. 25, 2024
- Modified: Jul. 07, 2025
-
4.8
MEDIUMCVE-2024-48233
mipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.... Read more
Affected Products : mipjz- Published: Oct. 25, 2024
- Modified: Jul. 07, 2025
-
6.8
MEDIUMCVE-2025-24987
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption