Latest CVE Feed
-
7.8
HIGHCVE-2025-24378
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-24377
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-23383
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-49601
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-13939
String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false... Read more
Affected Products : string\- Published: Mar. 28, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cryptography
-
9.1
CRITICALCVE-2025-24383
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to de... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-24382
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22398
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-49565
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-49564
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-49563
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-1860
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-31092
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget allows Stored XSS. This issue affects Click to Chat – WP Support All-in-One Floating Wid... Read more
Affected Products : click_to_chat- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-30232
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.... Read more
Affected Products : exim- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
5.9
MEDIUMCVE-2025-31101
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Ltd VaultRE Contact Form 7 allows Stored XSS.This issue affects VaultRE Contact Form 7: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-31031
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Job Colors for WP Job Manager allows Stored XSS.This issue affects Job Colors for WP Job Manager: from n/a through 1.0.4.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2025-2888
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. ... Read more
Affected Products : tough- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
-
5.7
MEDIUMCVE-2025-2887
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure... Read more
Affected Products : tough- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2025-2886
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, altering the target co... Read more
Affected Products : tough- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
5.7
MEDIUMCVE-2025-2885
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to... Read more
Affected Products : tough- Published: Mar. 27, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration