Latest CVE Feed
-
9.8
CRITICALCVE-2025-48913
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users ... Read more
Affected Products : cxf- Published: Aug. 08, 2025
- Modified: Aug. 14, 2025
-
5.9
MEDIUMCVE-2025-6572
The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could all... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
5.3
MEDIUMCVE-2025-54959
Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is exploited, an arbitrary file in the affected product may be disclosed.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.3
MEDIUMCVE-2025-54958
Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary OS commands may be executed on the affected product.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
4.6
MEDIUMCVE-2025-54940
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.... Read more
Affected Products : advanced_custom_fields- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
5.7
MEDIUMCVE-2024-58257
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
4.5
MEDIUMCVE-2024-58256
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
5.0
MEDIUMCVE-2024-58255
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
7.5
HIGHCVE-2025-8708
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipul... Read more
Affected Products : white-jotter- Published: Aug. 08, 2025
- Modified: Aug. 21, 2025
-
5.3
MEDIUMCVE-2025-8707
A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file AndroidManifest.xml of the component com.huuge.game.zjbox. The manipulation leads to improper export of android ap... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8706
A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /CommonSolution/CreateFunctionLog of the component Energy O... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8705
A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function of the file /WEAS_HomePage/GetTargetConfig of the component Energy Overview Module. The manipul... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8704
A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some unknown processing of the file /WEAS_AlarmResult/GetAlarmResultProcessList of the component Analys... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8703
A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of the file /WEAS_HomePage/GetAreaTrendChartData of the component Environmental Real-Time Data Modu... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
9.1
CRITICALCVE-2025-54887
jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft a... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
8.4
HIGHCVE-2025-54886
skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code execution. The Card.get_model function supports both joblib a... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
5.5
MEDIUMCVE-2025-54793
Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to a... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.5
MEDIUMCVE-2025-8702
A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the file /CommonSolution/GetVariableByOneIDNew of the component Historical Data Query Module. The mani... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
9.8
CRITICALCVE-2025-54952
An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
-
6.8
MEDIUMCVE-2025-54368
uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the archive's central directory. An attacker could contrive a... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025