Latest CVE Feed
-
6.5
MEDIUMCVE-2024-47224
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input in URLs. A succe... Read more
Affected Products : micollab- Published: Oct. 21, 2024
- Modified: Jun. 24, 2025
-
8.2
HIGHCVE-2024-31029
An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially crafted packets.... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-40494
Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet.... Read more
Affected Products : freecoap- Published: Oct. 22, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-46478
HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.... Read more
Affected Products : htmldoc- Published: Oct. 24, 2024
- Modified: Jun. 24, 2025
-
6.5
MEDIUMCVE-2024-40113
Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-40114
A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie to inject malicious JavaScript code.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-26136
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.... Read more
Affected Products : mysiteforme- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.... Read more
Affected Products : flowise- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-27622
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-27623
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-27624
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-27625
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, b... Read more
Affected Products : jenkins- Published: Mar. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-51165
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Dec. 10, 2024
- Modified: Jun. 24, 2025
-
9.1
CRITICALCVE-2024-55089
Rhymix 2.1.19 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function.... Read more
Affected Products : rhymix- Published: Dec. 18, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2024-56737
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.... Read more
Affected Products : grub2- Published: Dec. 29, 2024
- Modified: Jun. 24, 2025
-
5.3
MEDIUMCVE-2024-56738
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.... Read more
Affected Products : grub2- Published: Dec. 29, 2024
- Modified: Jun. 24, 2025
-
4.8
MEDIUMCVE-2024-11184
The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts... Read more
Affected Products : wp_enable_svg- Published: Jan. 02, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-55008
JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 inc... Read more
Affected Products : jatos- Published: Jan. 07, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-50658
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file... Read more
Affected Products : adportal- Published: Jan. 07, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-57427
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session... Read more
Affected Products : cinema_booking_system- Published: Feb. 06, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting