Latest CVE Feed
-
7.8
HIGHCVE-2025-43593
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-47104
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-47105
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-47106
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-30317
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2009-2631
Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Ga... Read more
- Published: Dec. 04, 2009
- Modified: Jun. 16, 2025
-
7.8
HIGHCVE-2024-37289
An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system i... Read more
Affected Products : apex_one- Published: Jun. 10, 2024
- Modified: Jun. 16, 2025
-
8.8
HIGHCVE-2025-3638
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.... Read more
Affected Products : moodle- Published: Apr. 25, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.8
HIGHCVE-2024-36304
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-p... Read more
Affected Products : apex_one- Published: Jun. 10, 2024
- Modified: Jun. 16, 2025
-
5.4
MEDIUMCVE-2025-45236
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.... Read more
Affected Products : dbsyncer- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-45237
Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.... Read more
Affected Products : dbsyncer- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-29573
Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.... Read more
Affected Products : mezzanine- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-45607
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.... Read more
Affected Products : itranswarp- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-23900
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller f... Read more
Affected Products : matrix_project- Published: Jan. 24, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2024-23740
An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.... Read more
Affected Products : kap- Published: Jan. 28, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2024-22076
MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.... Read more
Affected Products : print_server- Published: Jan. 23, 2024
- Modified: Jun. 16, 2025
-
7.5
HIGHCVE-2023-49549
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.... Read more
Affected Products : mjs- Published: Jan. 02, 2024
- Modified: Jun. 16, 2025
-
7.5
HIGHCVE-2023-49427
Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 16, 2025
-
3.3
LOWCVE-2023-46837
Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance, used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached memory before handing over the page to a gues... Read more
Affected Products : xen- Published: Jan. 05, 2024
- Modified: Jun. 16, 2025
-
6.3
MEDIUMCVE-2023-42887
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able to read arbitrary files.... Read more
Affected Products : macos- Published: Jan. 23, 2024
- Modified: Jun. 16, 2025