Latest CVE Feed
-
5.9
MEDIUMCVE-2023-33757
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.... Read more
- Published: Jan. 25, 2024
- Modified: Jun. 20, 2025
-
7.2
HIGHCVE-2023-31505
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.... Read more
Affected Products : cms- Published: Jan. 31, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2023-29055
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possi... Read more
Affected Products : kylin- Published: Jan. 29, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2022-4964
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.... Read more
Affected Products : ubuntu_pipewire-pulse- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2021-42146
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows r... Read more
Affected Products : tinydtls- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2021-42145
An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.... Read more
Affected Products : tinydtls- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2021-42144
Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information via crafted input to dtls_ccm_decrypt_message().... Read more
Affected Products : contiki-ng_tinydtls- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.1
CRITICALCVE-2021-42143
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a ClientHello handshake message. This bug allows remote attackers to cause a denial of service by sending a malformed ClientHe... Read more
Affected Products : tinydtls- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
6.1
MEDIUMCVE-2021-43635
A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.... Read more
- Published: Feb. 04, 2022
- Modified: Jun. 20, 2025
-
7.3
HIGHCVE-2025-1068
There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a ... Read more
- Published: Feb. 25, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Misconfiguration
-
7.3
HIGHCVE-2025-1067
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a specif... Read more
- Published: Feb. 25, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-35079
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.... Read more
Affected Products : inxedu- Published: May. 23, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-35080
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.... Read more
- Published: May. 23, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-35570
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute arbitrary code via uploading a crafted jsp file.... Read more
Affected Products : inxedu- Published: May. 23, 2024
- Modified: Jun. 20, 2025
-
7.8
HIGHCVE-2023-26604
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not set LESSSECURE to 1, and thus other... Read more
- Published: Mar. 03, 2023
- Modified: Jun. 20, 2025
-
9.1
CRITICALCVE-2024-31030
An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose information via a specially crafted packet.... Read more
Affected Products : freecoap- Published: May. 31, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-23751
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able t... Read more
Affected Products : llamaindex- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
8.8
HIGHCVE-2024-23750
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.... Read more
Affected Products : metagpt- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
7.5
HIGHCVE-2024-23732
The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.... Read more
Affected Products : embedchain- Published: Jan. 21, 2024
- Modified: Jun. 20, 2025
-
5.3
MEDIUMCVE-2024-23688
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is ... Read more
Affected Products : discovery- Published: Jan. 19, 2024
- Modified: Jun. 20, 2025