Latest CVE Feed
-
4.8
MEDIUMCVE-2023-36236
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.... Read more
Affected Products : bagisto- Published: Jan. 16, 2024
- Modified: Jun. 17, 2025
-
6.7
MEDIUMCVE-2023-32877
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08308070; Issue ID:... Read more
- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2023-25365
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3... Read more
Affected Products : october- Published: Feb. 08, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2023-25295
A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.... Read more
Affected Products : evewa3- Published: Jan. 17, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-47072
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..... Read more
Affected Products : enterprise_architect- Published: Jan. 31, 2024
- Modified: Jun. 17, 2025
-
3.8
LOWCVE-2020-26624
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2020-13878
IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+27ef heap-based out-of-bounds write.... Read more
Affected Products : b3d- Published: Jan. 05, 2024
- Modified: Jun. 17, 2025
-
4.6
MEDIUMCVE-2024-33791
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.... Read more
- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-33792
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.... Read more
- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
5.3
MEDIUMCVE-2024-33793
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.... Read more
- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-31673
Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.... Read more
Affected Products : kliqqi_cms- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2024-34467
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.... Read more
Affected Products : thinkphp- Published: May. 04, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2024-34468
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.... Read more
Affected Products : rukovoditel- Published: May. 04, 2024
- Modified: Jun. 17, 2025
-
7.1
HIGHCVE-2024-34469
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.... Read more
Affected Products : rukovoditel- Published: May. 04, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-34502
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST requ... Read more
- Published: May. 05, 2024
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2024-28521
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.... Read more
- Published: Mar. 21, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-28441
File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.... Read more
Affected Products : magicflue- Published: Mar. 22, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2024-29273
There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.... Read more
Affected Products : dzzoffice- Published: Mar. 22, 2024
- Modified: Jun. 17, 2025
-
7.8
HIGHCVE-2025-46567
LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on use... Read more
Affected Products : llama-factory- Published: May. 01, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-46568
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, e... Read more
Affected Products : stirling_pdf- Published: May. 01, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Server-Side Request Forgery