Latest CVE Feed
-
0.0
NONECVE-2025-28104
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-28103
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-27086
Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2024-57394
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by levera... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-29446
open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.1
CVSS31CVE-2025-28102
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-28099
opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
7.5
CVSS31CVE-2025-23174
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
8.1
CVSS31CVE-2025-43922
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
7.5
CVSS31CVE-2025-3857
When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, th... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
4.0
CVSS31CVE-2025-32793
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that ori... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-32431
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.5
CVSS31CVE-2025-28367
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2024-12543
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-2517
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
0.0
NONECVE-2025-2298
An improper authorization vulnerability in Dremio Software allows authenticated users to delete arbitrary files that the system has access to, including system files and files stored in remote locations such as S3, Azure Blob Storage, and local filesystem... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
9.8
CVSS31CVE-2025-29660
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
9.8
CVSS31CVE-2025-29659
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
9.8
CVSS31CVE-2025-29287
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.1
CVSS31CVE-2025-28121
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025