Latest CVE Feed
-
9.8
CRITICALCVE-2025-2777
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Published: May. 07, 2025
- Modified: Jun. 27, 2025
- Vuln Type: XML External Entity
-
5.9
MEDIUMCVE-2024-24818
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerabilit... Read more
Affected Products : espocrm- Published: Mar. 21, 2024
- Modified: Jun. 27, 2025
-
7.5
HIGHCVE-2024-28130
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigge... Read more
- Published: Apr. 23, 2024
- Modified: Jun. 27, 2025
-
7.5
HIGHCVE-2024-28640
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.... Read more
- Published: Mar. 16, 2024
- Modified: Jun. 27, 2025
-
6.3
MEDIUMCVE-2024-2241
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions ... Read more
Affected Products : workspace- Published: Mar. 07, 2024
- Modified: Jun. 27, 2025
-
7.3
HIGHCVE-2022-36263
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.... Read more
- Published: Aug. 19, 2022
- Modified: Jun. 27, 2025
-
6.5
MEDIUMCVE-2024-1316
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g.... Read more
- Published: Mar. 04, 2024
- Modified: Jun. 27, 2025
-
8.8
HIGHCVE-2024-27497
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.... Read more
- Published: Mar. 01, 2024
- Modified: Jun. 27, 2025
-
4.5
MEDIUMCVE-2024-3165
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. ... Read more
Affected Products : dotcms- Published: Apr. 01, 2024
- Modified: Jun. 27, 2025
-
4.5
MEDIUMCVE-2024-3164
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, sh... Read more
Affected Products : dotcms- Published: Apr. 01, 2024
- Modified: Jun. 27, 2025
-
8.1
HIGHCVE-2025-25950
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-25951
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-25952
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-27583
Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-27584
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name paramet... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-25953
Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.... Read more
Affected Products : academia_student_information_system- Published: Mar. 03, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-37087
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.... Read more
- Published: Jun. 25, 2024
- Modified: Jun. 27, 2025
-
6.8
MEDIUMCVE-2024-37086
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.... Read more
- Published: Jun. 25, 2024
- Modified: Jun. 27, 2025
-
4.9
MEDIUMCVE-2024-22275
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.... Read more
- Published: May. 21, 2024
- Modified: Jun. 27, 2025
-
7.2
HIGHCVE-2024-22274
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.... Read more
- Published: May. 21, 2024
- Modified: Jun. 27, 2025