Latest CVE Feed
-
8.6
HIGHCVE-2024-13617
The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server... Read more
Affected Products : downloadable_by_american_osteopathic_association- Published: Mar. 25, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
7.0
HIGHCVE-2025-2784
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.... Read more
Affected Products : enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions codeready_linux_builder +14 more products- Published: Apr. 03, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-5886
A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack may be initiate... Read more
Affected Products : emlog- Published: Jun. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-5978
A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to l... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-48013
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.... Read more
- Published: Jun. 11, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-48444
Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.... Read more
- Published: Jun. 11, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-48447
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.... Read more
- Published: Jun. 11, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6130
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation leads to bu... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6138
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ssid5g... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-4729
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. Th... Read more
- Published: May. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-4730
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation ... Read more
- Published: May. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4731
A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_typ... Read more
- Published: May. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4732
A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6ad... Read more
- Published: May. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4733
A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of... Read more
- Published: May. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2025-26468
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.... Read more
- Published: Jun. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-5934
A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The ... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2024-57186
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2024-57189
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-57190
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.... Read more
Affected Products : erxes- Published: Jun. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-48448
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.... Read more
- Published: Jun. 11, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Denial of Service