Latest CVE Feed
-
4.3
MEDIUMCVE-2024-25037
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.... Read more
- Published: Jan. 07, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2022-22363
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again... Read more
- Published: Jan. 07, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2021-20455
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks again... Read more
- Published: Jan. 07, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-25048
IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force... Read more
Affected Products : mq_appliance- Published: Apr. 27, 2024
- Modified: Jul. 03, 2025
-
4.7
MEDIUMCVE-2024-54173
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.... Read more
- Published: Feb. 28, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-0975
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.... Read more
- Published: Feb. 28, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-23225
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.... Read more
- Published: Feb. 28, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-51471
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.... Read more
Affected Products : mq_appliance- Published: Dec. 19, 2024
- Modified: Jul. 03, 2025
-
6.2
MEDIUMCVE-2024-52898
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.... Read more
- Published: Jan. 14, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2023-45177
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM X-Force ID: 268066.... Read more
- Published: Mar. 20, 2024
- Modified: Jul. 03, 2025
-
7.2
HIGHCVE-2024-3892
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.... Read more
- Published: May. 15, 2024
- Modified: Jul. 03, 2025
-
9.8
CRITICALCVE-2025-0332
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.... Read more
- Published: Feb. 12, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2024-10013
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.... Read more
- Published: Nov. 13, 2024
- Modified: Jul. 03, 2025
-
6.4
MEDIUMCVE-2025-4585
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.17 due to insufficient input sanitization and output escaping on user supplied attributes. Th... Read more
Affected Products : irm_newsroom- Published: Jun. 13, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4586
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.17 due to insufficient input sanitization and output escaping on user supplied attrib... Read more
Affected Products : irm_newsroom- Published: Jun. 13, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4584
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.17 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : irm_newsroom- Published: Jun. 13, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-24992
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
-
7.3
HIGHCVE-2025-24994
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-20169
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
5.8
MEDIUMCVE-2024-20363
Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to inco... Read more
- Published: May. 22, 2024
- Modified: Jul. 03, 2025