Latest CVE Feed
-
6.1
MEDIUMCVE-2022-36350
Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : pukiwiki- Published: Aug. 23, 2022
- Modified: Jun. 30, 2025
-
5.4
MEDIUMCVE-2020-35509
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality ... Read more
- Published: Aug. 23, 2022
- Modified: Jun. 30, 2025
-
4.8
MEDIUMCVE-2025-6494
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-bas... Read more
Affected Products : nokogiri- Published: Jun. 22, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6490
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based ... Read more
Affected Products : nokogiri- Published: Jun. 22, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-53621
A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-47310
A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2023-28909
A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can lev... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2023-28908
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vul... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
6.7
MEDIUMCVE-2023-28907
There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered i... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2023-28906
A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative access to the system. The vulnerability was originally discovered in Skoda Superb I... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2023-28905
A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V00358... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
5.2
MEDIUMCVE-2023-28904
A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at ... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
3.3
LOWCVE-2023-28903
An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a denial-of-service of the infotainment system.... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
3.3
LOWCVE-2023-28902
An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Skoda Superb III ca... Read more
Affected Products :- Published: Jun. 28, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-50182
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or fal... Read more
Affected Products : urllib3- Published: Jun. 19, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Misconfiguration
-
7.0
HIGHCVE-2025-45143
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-26074
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-38057
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1. ... Read more
Affected Products : th_advance_product_search- Published: Mar. 25, 2024
- Modified: Jun. 30, 2025
-
9.1
CRITICALCVE-2024-4399
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack... Read more
- Published: May. 23, 2024
- Modified: Jun. 30, 2025
-
6.9
MEDIUMCVE-2025-53122
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. Users should upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian... Read more
- Published: Jun. 26, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection