Latest CVE Feed
-
4.9
MEDIUMCVE-2024-40553
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.... Read more
Affected Products : tmall_demo- Published: Jul. 15, 2024
- Modified: Jun. 13, 2025
-
5.0
MEDIUMCVE-2025-32102
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.... Read more
Affected Products : crushftp- Published: Apr. 15, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Server-Side Request Forgery
-
5.0
MEDIUMCVE-2025-32103
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.... Read more
Affected Products : crushftp- Published: Apr. 15, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-49186
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.... Read more
Affected Products :- Published: Jun. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-49182
Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.... Read more
Affected Products :- Published: Jun. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Information Disclosure
-
9.0
CRITICALCVE-2024-55585
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.... Read more
Affected Products :- Published: Jun. 07, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-6538
A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed ... Read more
Affected Products : openshift_container_platform- Published: Nov. 25, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2025-5593
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5594
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component SET Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2024-50677
A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.... Read more
- Published: Dec. 06, 2024
- Modified: Jun. 13, 2025
-
4.3
MEDIUMCVE-2024-48900
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.... Read more
Affected Products : moodle- Published: Nov. 13, 2024
- Modified: Jun. 13, 2025
-
7.2
HIGHCVE-2024-46213
REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.... Read more
Affected Products : redaxo- Published: Oct. 16, 2024
- Modified: Jun. 13, 2025
-
5.5
MEDIUMCVE-2024-48241
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.... Read more
Affected Products : radare2- Published: Oct. 30, 2024
- Modified: Jun. 13, 2025
-
6.5
MEDIUMCVE-2024-48052
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources... Read more
Affected Products : gradio- Published: Nov. 04, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2024-6766
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
Affected Products : shortcodes_ultimate- Published: Aug. 06, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2021-20588
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and ... Read more
Affected Products : gx_works3 gt_designer3 gt_softgot2000 cpu_module_logging_configuration_tool cw_configurator gx_logviewer gx_works2 m_commdtm-hart m_commdtm-io-link melfa-works +35 more products- Published: Feb. 19, 2021
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2021-20587
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions ... Read more
Affected Products : gx_works3 gt_designer3 gt_softgot2000 cpu_module_logging_configuration_tool cw_configurator gx_logviewer gx_works2 m_commdtm-hart m_commdtm-io-link melfa-works +35 more products- Published: Feb. 19, 2021
- Modified: Jun. 13, 2025
-
7.3
HIGHCVE-2024-40560
Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.... Read more
Affected Products : tmall_demo- Published: Jul. 15, 2024
- Modified: Jun. 13, 2025
-
5.3
MEDIUMCVE-2024-40555
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : tmall_demo- Published: Jul. 15, 2024
- Modified: Jun. 13, 2025
-
6.8
MEDIUMCVE-2024-4977
The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
- Published: Jul. 13, 2024
- Modified: Jun. 13, 2025