Latest CVE Feed
-
5.3
MEDIUMCVE-2025-6603
A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the arg... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-52569
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-6258
The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-52479
HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF ch... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34044
A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute ... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34049
An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails to properly sanitize user input in the target_addr parameter of the f... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
5.0
MEDIUMCVE-2025-6706
An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggrega... Read more
Affected Products : mongodb- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
4.2
MEDIUMCVE-2025-6707
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administrator. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to ... Read more
Affected Products : mongodb- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6561
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator c... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-5535
The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. T... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-5590
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-5459
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in ... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-5366
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-5015
A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
0.0
NONECVE-2025-3722
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesyst... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
0.0
NONECVE-2025-3773
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-52999
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a Sta... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-52890
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` a... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-5966
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2023-44915
A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting