Latest CVE Feed
-
7.8
HIGHCVE-2025-24080
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.... Read more
Affected Products : office 365_apps office_long_term_servicing_channel office_2016 office_2024 office_2021 office_2019- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
-
7.8
HIGHCVE-2025-24082
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.... Read more
Affected Products : office 365_apps excel office_online_server office_long_term_servicing_channel office_macos_2024 office_macos_2021 excel_2016 office_2024 office_2021 +1 more products- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
-
7.8
HIGHCVE-2024-52561
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files.... Read more
Affected Products : parallels_desktop- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-54189
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken, a root service writes to a file owned by a normal user. By using a hard lin... Read more
Affected Products : parallels_desktop- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-31359
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by an attacker to write to arbitrary files, potentially leading to privilege es... Read more
Affected Products : parallels_desktop- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-5382
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.... Read more
Affected Products : devolutions_server- Published: Jun. 05, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-24078
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-24077
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.... Read more
Affected Products : office 365_apps office_long_term_servicing_channel office_macos_2024 office_macos_2021 office_2024- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
-
9.8
CRITICALCVE-2025-5493
A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file /e3api/api/main/ToJsonByControlName. The manipulation of the argument data leads to sql injec... Read more
Affected Products : channel_middleware_product- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-24079
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
7.0
HIGHCVE-2025-24070
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-24048
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows windows_11_23h2 +4 more products- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-46548
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommend... Read more
- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-5063
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: May. 27, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-31368
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. ... Read more
Affected Products : soledad- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
5.4
MEDIUMCVE-2024-31369
Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. ... Read more
Affected Products : soledad- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
7.1
HIGHCVE-2024-31367
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. ... Read more
Affected Products : soledad- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
5.5
MEDIUMCVE-2025-48888
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --allow-read --deny-read main.ts` results in allowed, even though 'deny' should be stronger. The result is the... Read more
Affected Products : deno- Published: Jun. 04, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-48934
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` method ignores any variables listed in the `--deny-env` option of the `deno run` command. When looking at the documentation of the `--d... Read more
Affected Products : deno- Published: Jun. 04, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-48935
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using `ATTACH DATABASE` statement. Version 2.2.5 contains a patc... Read more
Affected Products : deno- Published: Jun. 04, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization