Latest CVE Feed
-
4.3
MEDIUMCVE-2022-23689
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the ... Read more
- Published: Sep. 06, 2022
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2022-1807
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.... Read more
- Published: Sep. 07, 2022
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.... Read more
Affected Products : kirby- Published: Aug. 24, 2022
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-42565
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 17, 2025
-
5.3
MEDIUMCVE-2024-45191
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementatio... Read more
Affected Products : olm- Published: Aug. 22, 2024
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2024-21169
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comp... Read more
Affected Products : marketing- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2024-21154
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
8.1
HIGHCVE-2024-21153
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged att... Read more
Affected Products : process_manufacturing_product_development- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
7.4
HIGHCVE-2024-21147
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; O... Read more
Affected Products : active_iq_unified_manager oncommand_insight oncommand_workflow_automation jdk jre graalvm bootstrap_os hci_compute_node graalvm_for_jdk bluexp +1 more products- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
8.1
HIGHCVE-2024-21152
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with ... Read more
Affected Products : process_manufacturing_financials- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-34982
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : lylme_spage- Published: May. 17, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2024-36674
LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.... Read more
Affected Products : lylme_spage- Published: Jun. 03, 2024
- Modified: Jun. 17, 2025
-
5.3
MEDIUMCVE-2024-45192
An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no long... Read more
Affected Products : olm- Published: Aug. 22, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2024-45193
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects produc... Read more
Affected Products : olm- Published: Aug. 22, 2024
- Modified: Jun. 17, 2025
-
4.8
MEDIUMCVE-2025-4325
A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of the file /admin/category/add.do of the component Category Management Page. The manipulation of the argument Name leads to cross site sc... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-4326
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page. The manipulation leads to cross site scripting. The attack may be initiat... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2025-32441
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack sessio... Read more
Affected Products : rack- Published: May. 07, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Race Condition
-
6.1
MEDIUMCVE-2024-28063
Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.... Read more
Affected Products : totemomail- Published: May. 18, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2025-46727
Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parame... Read more
Affected Products : rack- Published: May. 07, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2024-55651
i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuári... Read more
Affected Products : i-educar- Published: May. 08, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting