Latest CVE Feed
-
7.8
HIGHCVE-2025-43573
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43574
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43575
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user in... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43576
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43577
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interact... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-43578
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-43579
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2024-28752
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including ... Read more
- Published: Mar. 15, 2024
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2024-4825
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.... Read more
Affected Products : cockpit- Published: May. 14, 2024
- Modified: Jun. 27, 2025
-
5.5
MEDIUMCVE-2024-36307
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an attacker must first obtain the abi... Read more
Affected Products : apex_one- Published: Jun. 10, 2024
- Modified: Jun. 27, 2025
-
9.0
HIGHCVE-2025-6128
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url lead... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-4548
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perfor... Read more
Affected Products : diaenergie- Published: May. 06, 2024
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2024-4547
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perf... Read more
Affected Products : diaenergie- Published: May. 06, 2024
- Modified: Jun. 27, 2025
-
6.5
MEDIUMCVE-2024-27439
An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not ... Read more
Affected Products : wicket- Published: Mar. 19, 2024
- Modified: Jun. 27, 2025
-
3.5
LOWCVE-2024-4226
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.... Read more
Affected Products : octopus_server- Published: Apr. 30, 2024
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2025-2777
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Published: May. 07, 2025
- Modified: Jun. 27, 2025
- Vuln Type: XML External Entity
-
5.9
MEDIUMCVE-2024-24818
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerabilit... Read more
Affected Products : espocrm- Published: Mar. 21, 2024
- Modified: Jun. 27, 2025
-
7.5
HIGHCVE-2024-28130
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigge... Read more
- Published: Apr. 23, 2024
- Modified: Jun. 27, 2025
-
7.5
HIGHCVE-2024-28640
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.... Read more
- Published: Mar. 16, 2024
- Modified: Jun. 27, 2025
-
6.3
MEDIUMCVE-2024-2241
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions ... Read more
Affected Products : workspace- Published: Mar. 07, 2024
- Modified: Jun. 27, 2025