Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    CVSS31
    CVE-2024-11186

    On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-pre... Read more

    Affected Products : cloudvision_portal
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-4098

    Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape.... Read more

    Affected Products : cscape
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 5.5

    CVSS31
    CVE-2025-30102

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more

    Affected Products : powerscale_onefs
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 4.4

    CVSS31
    CVE-2025-30101

    Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service a... Read more

    Affected Products : powerscale_onefs
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 7.5

    CVSS31
    CVE-2025-1948

    In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to alloca... Read more

    Affected Products : jetty
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 7.2

    CVSS31
    CVE-2024-13009

    In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.... Read more

    Affected Products : jetty
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 2.8

    CVSS31
    CVE-2025-44021

    OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conduc... Read more

    Affected Products : ironic
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 9.1

    CVSS31
    CVE-2025-26847

    An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 9.8

    CVSS31
    CVE-2025-26845

    An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 3.1

    CVSS31
    CVE-2025-4132

    Rapid7 Corporate Website prior to May 2nd 2025, suffered from a URL Redirection to Untrusted Site ('Open Redirect') vulnerability whereby, due to misconfigured headers, an attacker could successfully redirect users to a malicious site of their control. T... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45847

    ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45846

    ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45845

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45844

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45843

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45842

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-45841

    TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 0.0

    NONE
    CVE-2025-43926

    An issue was discovered in Znuny through 6.5.14 and 7.x through 7.1.6. Custom AJAX calls to the AgentPreferences UpdateAJAX subaction can be used to set user preferences with arbitrary keys. When fetching user data via GetUserData, these keys and values a... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 9.8

    CVSS31
    CVE-2025-26844

    An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
  • 7.5

    CVSS31
    CVE-2025-26842

    An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.... Read more

    Affected Products :
    • Published: May. 08, 2025
    • Modified: May. 08, 2025
Showing 20 of 283 Results
© cvefeed.io
Latest DB Update: May. 09, 2025 20:32