Latest CVE Feed
-
5.9
MEDIUMCVE-2024-29120
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrato... Read more
Affected Products : streampark- Published: Jul. 17, 2024
- Modified: Jun. 23, 2025
-
4.4
MEDIUMCVE-2025-21495
Vulnerability in the MySQL Enterprise Firewall product of Oracle MySQL (component: Firewall). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attac... Read more
Affected Products : mysql_enterprise_firewall- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-21557
Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Expre... Read more
Affected Products : application_express- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28056
rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.... Read more
Affected Products : rebuild- Published: May. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-43946
TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).... Read more
Affected Products : ddi- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
4.5
MEDIUMCVE-2025-21568
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileged attacker with... Read more
Affected Products : hyperion_data_relationship_management- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.6
MEDIUMCVE-2025-21569
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged attacker with netw... Read more
Affected Products : hyperion_data_relationship_management- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2025-21583
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to ... Read more
- Published: Apr. 15, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-43947
Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.... Read more
Affected Products : klims- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2025-30721
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the ... Read more
Affected Products : mysql_server- Published: Apr. 15, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-30691
Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via... Read more
- Published: Apr. 15, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-21552
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker ... Read more
Affected Products : jd_edwards_enterpriseone_orchestrator- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
4.2
MEDIUMCVE-2025-21553
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure pr... Read more
- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-21550
Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.1, 8.1.2.7 and 8.1.2.8. Easily exploitable vulnerability all... Read more
Affected Products : financial_services_behavior_detection_platform- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-21549
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to c... Read more
Affected Products : weblogic_server- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-21547
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthent... Read more
Affected Products : hospitality_opera_5- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-21541
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : workflow- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-21535
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access v... Read more
Affected Products : weblogic_server- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-21533
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the ... Read more
Affected Products : vm_virtualbox- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-21516
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via H... Read more
- Published: Jan. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization