Latest CVE Feed
-
10.0
CRITICALCVE-2025-1744
Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.... Read more
Affected Products : radare2- Published: Feb. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2025-6842
A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_user.php. The manipulation of the argument ID leads to sql injection. The attack may be ... Read more
Affected Products : product_inventory_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47787
Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP ... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-39730
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click ... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-36026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-36027
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click action... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.1
CRITICALCVE-2024-37770
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.... Read more
Affected Products : 14finger- Published: Jul. 10, 2024
- Modified: Jul. 01, 2025
-
7.5
HIGHCVE-2024-37767
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.... Read more
Affected Products : 14finger- Published: Jul. 05, 2024
- Modified: Jul. 01, 2025
-
4.3
MEDIUMCVE-2024-23937
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. ... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2024-23929
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypa... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-23921
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-23920
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboard... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 23, 2023
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2023-40890
A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally inp... Read more
Affected Products : zbar- Published: Aug. 29, 2023
- Modified: Jul. 01, 2025
-
5.4
MEDIUMCVE-2023-40282
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.... Read more
- Published: Aug. 23, 2023
- Modified: Jul. 01, 2025
-
7.5
HIGHCVE-2023-32559
A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventua... Read more
Affected Products : node.js- Published: Aug. 24, 2023
- Modified: Jul. 01, 2025
-
8.8
HIGHCVE-2024-50930
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.... Read more
- Published: Dec. 10, 2024
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2025-6822
A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql inject... Read more
Affected Products : inventory_management_system- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2024-50931
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.... Read more
- Published: Dec. 10, 2024
- Modified: Jul. 01, 2025
-
5.9
MEDIUMCVE-2024-30192
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins for Pinterest: from n/a through 1.8.2. ... Read more
Affected Products : gs_pinterest_portfolio- Published: Mar. 27, 2024
- Modified: Jul. 01, 2025