Latest CVE Feed
-
5.0
MEDIUMCVE-2025-0691
Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.... Read more
Affected Products : devolutions_server- Published: Jun. 05, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
5.0
MEDIUMCVE-2025-3768
Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.... Read more
Affected Products : devolutions_server- Published: Jun. 05, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-2975
A race condition was identified through which privilege escalation was possible in certain configurations.... Read more
- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
6.5
MEDIUMCVE-2025-4679
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : active_backup_for_microsoft_365- Published: May. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2024-49194
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could pote... Read more
Affected Products :- Published: Dec. 17, 2024
- Modified: Jul. 02, 2025
-
4.3
MEDIUMCVE-2025-52711
Cross-Site Request Forgery (CSRF) vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Cross Site Request Forgery.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a thro... Read more
Affected Products : post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.4
HIGHCVE-2024-8676
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod reques... Read more
Affected Products : openshift_container_platform- Published: Nov. 26, 2024
- Modified: Jul. 02, 2025
-
4.6
MEDIUMCVE-2024-41927
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, ... Read more
- Published: Sep. 04, 2024
- Modified: Jul. 02, 2025
-
9.8
CRITICALCVE-2025-37092
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37093
An authentication bypass vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-37094
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-5447
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ss... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-46611
Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.... Read more
Affected Products : ema- Published: May. 12, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2023-47466
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.... Read more
Affected Products : taglib- Published: May. 22, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5108
A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/controller/Payment.php of the component ZIP File Handler. The manipulation of the argument params leads to unr... Read more
Affected Products : shopxo- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Misconfiguration
-
7.6
HIGHCVE-2025-32794
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to injec... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-32967
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrato... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-43860
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privile... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-53427
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter... Read more
Affected Products : jq- Published: Feb. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25361
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.... Read more
Affected Products : publiccms- Published: Mar. 06, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication