Latest CVE Feed
-
9.8
CRITICALCVE-2025-32799
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives ... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-48866
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `saniti... Read more
- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2023-4509
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.... Read more
- Published: Apr. 18, 2024
- Modified: Jul. 02, 2025
-
8.8
HIGHCVE-2025-5438
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. T... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5439
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. Affected by this issue is the function verifyFacebookLike of the file /goform/ve... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37095
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-5440
A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the file /goform/NTP. The manipulation of the argu... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-2955
A vulnerability has been found in TOTOLINK A3000RU up to 5.9c.5185 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/ExportIbmsConfig.sh of the component IBMS Configuration File Handler. The manipulation leads to ... Read more
- Published: Mar. 30, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-2688
A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation l... Read more
- Published: Mar. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-37096
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-48927
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.... Read more
Affected Products : telemessage- Actively Exploited
- Published: May. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2025-48928
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.... Read more
Affected Products : telemessage- Actively Exploited
- Published: May. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-37089
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-46178
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, lea... Read more
Affected Products : cloudclassroom-php_project- Published: Jun. 09, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-37091
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6688
The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possib... Read more
Affected Products : simple_payment- Published: Jun. 27, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-37090
A server-side request forgery vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-5196
A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The a... Read more
Affected Products : wing_ftp_server- Published: May. 26, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
5.8
MEDIUMCVE-2025-1611
A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible to in... Read more
Affected Products : shopxo- Published: Feb. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6302
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Comment leads to stack-based buffer ov... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption