Latest CVE Feed
-
6.1
MEDIUMCVE-2024-39174
A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.... Read more
Affected Products : yzmcms- Published: Jul. 05, 2024
- Modified: Jun. 13, 2025
-
5.5
MEDIUMCVE-2024-37674
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.... Read more
Affected Products : moodle- Published: Jun. 20, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2025-46983
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46984
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46985
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46986
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46987
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-53425
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash.... Read more
Affected Products : assimp- Published: Nov. 21, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2025-46988
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2024-52771
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.... Read more
Affected Products : dedebiz- Published: Nov. 20, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2024-52770
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : dedebiz- Published: Nov. 20, 2024
- Modified: Jun. 13, 2025
-
7.2
HIGHCVE-2024-52769
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : dedebiz- Published: Nov. 20, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2025-26846
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.... Read more
Affected Products : znuny- Published: May. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-44830
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.... Read more
Affected Products : engineercms- Published: May. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45779
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.... Read more
- Published: May. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-44175
Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.... Read more
- Published: May. 12, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
8.6
HIGHCVE-2024-34199
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.... Read more
Affected Products : tinyweb- Published: May. 14, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2024-34243
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.... Read more
Affected Products : konga- Published: May. 14, 2024
- Modified: Jun. 13, 2025
-
6.2
MEDIUMCVE-2024-34250
A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.... Read more
Affected Products : webassembly_micro_runtime- Published: May. 06, 2024
- Modified: Jun. 13, 2025
-
7.5
HIGHCVE-2024-34251
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.... Read more
Affected Products : webassembly_micro_runtime- Published: May. 06, 2024
- Modified: Jun. 13, 2025