Latest CVE Feed
-
5.4
MEDIUMCVE-2025-36042
IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials... Read more
- Published: Aug. 22, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-55573
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : new_api- Published: Aug. 22, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-55574
Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code... Read more
Affected Products : docmost- Published: Aug. 25, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-29901
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in... Read more
Affected Products : file_station- Published: Aug. 26, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-55526
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py... Read more
- Published: Aug. 26, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-32213
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.... Read more
Affected Products : lomag_warehouse_management- Published: May. 01, 2024
- Modified: Sep. 15, 2025
-
8.8
HIGHCVE-2025-33073
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +9 more products- Published: Jun. 10, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Authorization
-
2.1
LOWCVE-2025-27238
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.... Read more
Affected Products : zabbix- Published: Sep. 12, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-30078
Windows Wi-Fi Driver Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +9 more products- Published: Jun. 11, 2024
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43018
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43017
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43016
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43015
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43014
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
9.8
CRITICALCVE-2024-33078
Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.... Read more
Affected Products : libpag- Published: May. 01, 2024
- Modified: Sep. 15, 2025
-
8.8
HIGHCVE-2024-33428
Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.... Read more
Affected Products : phiola- Published: May. 01, 2024
- Modified: Sep. 15, 2025
-
6.5
MEDIUMCVE-2025-53640
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could... Read more
Affected Products : indico- Published: Jul. 14, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2025-7883
A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to comma... Read more
Affected Products : control_center- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-7884
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authent... Read more
Affected Products : control_center- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-7885
A vulnerability, which was classified as problematic, has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument hostname/port leads to cross site sc... Read more
Affected Products : webssh- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting