Latest CVE Feed
-
4.8
MEDIUMCVE-2025-6496
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads to null pointer dereference. Local access is required to ... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6497
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The e... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2024-3511
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a s... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-52921
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Functio... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-6512
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-6513
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
2.7
LOWCVE-2025-52968
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-lin... Read more
Affected Products : xdg-utils- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.1
MEDIUMCVE-2025-6509
A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the file /src/main/java/controller/SimpleController.java. T... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-6518
A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation ... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2021-47688
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-34022
A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in ... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2025-34030
An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can in... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-6498
A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit ha... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-6492
A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file marktext/src/main/utils/index.js. The manipulation leads to inefficient r... Read more
Affected Products : marktext- Published: Jun. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-6499
A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_parse_multiline_string of the file src/ucl_parser.c. The manipulation leads to heap-based buffer overflow. The attack ne... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.6
CRITICALCVE-2024-45347
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-6375
A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer dereference. The attack needs to ... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-6545
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cryptography
-
4.3
MEDIUMCVE-2025-52923
Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.... Read more
Affected Products : atrust- Published: Jun. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2025-52926
In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025