Latest CVE Feed
-
6.5
MEDIUMCVE-2025-10473
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the component Blacklist Handler. The manipulation results in sql injection. The attack ... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-10472
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path le... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-30078
Windows Wi-Fi Driver Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 +9 more products- Published: Jun. 11, 2024
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43018
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43017
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43016
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43015
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
6.1
MEDIUMCVE-2022-43014
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.... Read more
Affected Products : opencats- Published: Oct. 19, 2022
- Modified: Sep. 15, 2025
-
9.8
CRITICALCVE-2024-33078
Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.... Read more
Affected Products : libpag- Published: May. 01, 2024
- Modified: Sep. 15, 2025
-
8.8
HIGHCVE-2024-33428
Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.... Read more
Affected Products : phiola- Published: May. 01, 2024
- Modified: Sep. 15, 2025
-
6.5
MEDIUMCVE-2025-53640
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could... Read more
Affected Products : indico- Published: Jul. 14, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2025-7883
A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to comma... Read more
Affected Products : control_center- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-7884
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authent... Read more
Affected Products : control_center- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-7885
A vulnerability, which was classified as problematic, has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument hostname/port leads to cross site sc... Read more
Affected Products : webssh- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-7887
A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file template.inc.php. The manipulation of the argument path leads to cross site scripting. The attack can be init... Read more
Affected Products : wikidocs- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-7889
A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to impr... Read more
Affected Products : callapp- Published: Jul. 20, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-55213
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.... Read more
Affected Products : file_explorer- Published: Feb. 07, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-55214
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.... Read more
Affected Products : file_explorer- Published: Feb. 07, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-22994
O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.... Read more
Affected Products : o2oa- Published: Jan. 31, 2025
- Modified: Sep. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-36626
In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.... Read more
Affected Products : prestashop- Published: Nov. 29, 2024
- Modified: Sep. 15, 2025