Latest CVE Feed
-
9.8
CRITICALCVE-2025-8972
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be ini... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
6.1
MEDIUMCVE-2025-52335
EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.... Read more
Affected Products : eyoucms- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
6.7
MEDIUMCVE-2025-21110
Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.... Read more
Affected Products : data_lakehouse- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2024-11944
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices. Authentication is not... Read more
- Published: Dec. 30, 2024
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-8971
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument val-username leads to sql injection. The at... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-8970
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/booking.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the atta... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-8969
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-8968
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/disapprove_user.php. The manipulation of the argument ID leads to sql injection. The... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-8949
A vulnerability was identified in D-Link DIR-825 2.10. Affected by this vulnerability is the function get_ping_app_stat of the file ping_response.cgi of the component httpd. The manipulation of the argument ping_ipaddr leads to stack-based buffer overflow... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
-
6.5
MEDIUMCVE-2024-11946
iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations of iXsystems TrueNAS de... Read more
- Published: Dec. 30, 2024
- Modified: Aug. 18, 2025
-
6.5
MEDIUMCVE-2025-21104
Dell NetWorker, versions prior to 19.12.0.1 and versions prior to 19.11.0.4, contain(s) an Open Redirect Vulnerability in NMC. An unauthenticated attacker with remoter access could potentially exploit this vulnerability, leading to a targeted application ... Read more
- Published: Mar. 13, 2025
- Modified: Aug. 18, 2025
-
8.7
HIGHCVE-2023-28831
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker ... Read more
Affected Products : simatic_s7-1500_software_controller_firmware simatic_drive_controller_cpu_1504d_tf_firmware simatic_drive_controller_cpu_1507d_tf_firmware simatic_s7-1500_cpu_1510sp_f-1_pn_firmware simatic_s7-1500_cpu_1510sp-1_pn_firmware simatic_s7-1500_cpu_1511-1_pn_firmware simatic_s7-1500_cpu_1511c-1_pn_firmware simatic_s7-1500_cpu_1511f-1_pn_firmware simatic_s7-1500_cpu_1511t-1_pn_firmware simatic_s7-1500_cpu_1511tf-1_pn_firmware +150 more products- EPSS Score: %0.43
- Published: Sep. 12, 2023
- Modified: Aug. 18, 2025
-
4.4
MEDIUMCVE-2025-29768
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filen... Read more
- Published: Mar. 13, 2025
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2025-2449
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vu... Read more
Affected Products : flexlogger- Published: Mar. 18, 2025
- Modified: Aug. 18, 2025
-
8.8
HIGHCVE-2025-2450
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit ... Read more
Affected Products : vision_builder_ai- Published: Mar. 18, 2025
- Modified: Aug. 18, 2025
-
7.5
HIGHCVE-2023-38272
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 could allow a user with access to the network to obtain sensitive information from CLI arguments.... Read more
Affected Products : cloud_pak_system- Published: Mar. 27, 2025
- Modified: Aug. 18, 2025
-
4.4
MEDIUMCVE-2025-29989
Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.... Read more
- Published: Apr. 10, 2025
- Modified: Aug. 18, 2025
-
7.8
HIGHCVE-2023-6377
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases wh... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_eus x_server libssh tigervnc xwayland- EPSS Score: %0.41
- Published: Dec. 13, 2023
- Modified: Aug. 18, 2025
-
4.1
MEDIUMCVE-2025-45582
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an ... Read more
Affected Products : tar- Published: Jul. 11, 2025
- Modified: Aug. 18, 2025
-
7.5
HIGHCVE-2025-8671
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening... Read more
Affected Products : h2o- Published: Aug. 13, 2025
- Modified: Aug. 17, 2025