Latest CVE Feed
-
9.0
HIGHCVE-2025-6111
A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. The attack ca... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6110
A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6113
A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. It is possible to launch the... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47868
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RT... Read more
Affected Products : nuttx- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-6119
A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the function Assimp::BVHLoader::ReadNodeChannels in the library assimp/code/AssetLib/BVH/BVHLoader.cpp. The manipulation of the argument pNo... Read more
Affected Products : assimp- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47869
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc application. In this example application device stats structure that stored remotely provided parameters had har... Read more
Affected Products : nuttx- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-6120
A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in the library assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The manipulation leads to heap-... Read more
Affected Products : assimp- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
10.0
HIGHCVE-2025-6121
A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is the function get_pure_content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to stac... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2024-35432
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.... Read more
Affected Products : zkbio_cvsecurity- Published: May. 30, 2024
- Modified: Jun. 17, 2025
-
9.1
CRITICALCVE-2025-28384
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2024-21122
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : peoplesoft_enterprise_hcm_shared_components- Published: Jul. 16, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2025-28382
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2025-47091
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-35431
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.... Read more
Affected Products : zkbio_cvsecurity- Published: May. 30, 2024
- Modified: Jun. 17, 2025
-
8.1
HIGHCVE-2024-35433
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.... Read more
Affected Products : zkbio_cvsecurity- Published: May. 30, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-28000
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from 1.9 through 6.3.0.1.... Read more
Affected Products : litespeed_cache- Published: Aug. 21, 2024
- Modified: Jun. 17, 2025
-
8.1
HIGHCVE-2024-11917
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_call... Read more
Affected Products : jobsearch_wp_job_board- Published: Apr. 25, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2023-45256
Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, valid... Read more
Affected Products :- Published: Jun. 12, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2023-26159
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An att... Read more
- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2025-28381
A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure