Latest CVE Feed
-
8.2
HIGHCVE-2024-13484
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects... Read more
Affected Products :- Published: Jan. 28, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-28715
Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.... Read more
Affected Products : doracms- Published: Mar. 19, 2024
- Modified: Jun. 24, 2025
-
6.6
MEDIUMCVE-2024-41712
A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to ... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2024-41714
A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insuf... Read more
- Published: Oct. 21, 2024
- Modified: Jun. 24, 2025
-
6.5
MEDIUMCVE-2024-47224
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A succe... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jun. 24, 2025
-
8.2
HIGHCVE-2024-31029
An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially crafted packets.... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-40494
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-46478
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.... Read more
Affected Products : htmldoc- Published: Oct. 24, 2024
- Modified: Jun. 24, 2025
-
6.5
MEDIUMCVE-2024-40113
Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-40114
A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-26136
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.... Read more
Affected Products : mysiteforme- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.... Read more
Affected Products : flowise- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-27622
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-27623
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-27624
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-27625
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, b... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-51165
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Dec. 10, 2024
- Modified: Jun. 24, 2025
-
9.1
CRITICALCVE-2024-55089
Rhymix 2.1.19 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function.... Read more
Affected Products : rhymix- Published: Dec. 18, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2024-56737
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.... Read more
Affected Products : grub2- Published: Dec. 29, 2024
- Modified: Jun. 24, 2025
-
5.3
MEDIUMCVE-2024-56738
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.... Read more
Affected Products : grub2- Published: Dec. 29, 2024
- Modified: Jun. 24, 2025