Latest CVE Feed
-
10.0
CRITICALCVE-2025-48748
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.... Read more
Affected Products : directory_manager- Published: May. 29, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2025-1378
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached l... Read more
Affected Products : radare2- Published: Feb. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5330
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component RETR Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: May. 29, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5331
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploi... Read more
- Published: May. 29, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-45855
An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : erupt- Published: Jun. 03, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommen... Read more
Affected Products : inlong- Published: Jun. 06, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
9.0
HIGHCVE-2025-5875
A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function sub_69064 of the file /bin/main. The manipulation of the argument text leads to buffer overflow. It is pos... Read more
- Published: Jun. 09, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-45001
react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.... Read more
Affected Products : react-native-keys- Published: Jun. 09, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-45002
Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.... Read more
Affected Products : vigybag- Published: Jun. 09, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-5154
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.... Read more
- Published: Jun. 12, 2024
- Modified: Jun. 23, 2025
-
8.7
HIGHCVE-2025-49080
There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack compl... Read more
Affected Products : secure_access- Published: Jun. 12, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-46096
Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component... Read more
Affected Products : solon- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-28386
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-40570
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.... Read more
Affected Products : seacms- Published: Jun. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-29976
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 sharepoint_server windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 +8 more products- Published: May. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-29840
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +3 more products- Published: May. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29659
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.... Read more
- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29660
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially... Read more
- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-28102
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.... Read more
Affected Products : flaskblog- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57394
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by levera... Read more
Affected Products : tianqing_endpoint_security_management_system- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal