Latest CVE Feed
-
7.5
HIGHCVE-2025-29313
Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to cause a Denial of Service (DoS).... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-29312
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.... Read more
Affected Products : onos- Published: Mar. 24, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-29311
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.... Read more
Affected Products : onos- Published: Mar. 24, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-29310
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.... Read more
Affected Products : onos- Published: Mar. 24, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29135
A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.... Read more
- Published: Mar. 24, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29100
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.... Read more
- Published: Mar. 24, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-2709
A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiat... Read more
Affected Products : ufida_erp-nc- Published: Mar. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-2708
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface. The manipulation of the argument path ... Read more
- Published: Mar. 24, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-2231
PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this ... Read more
- Published: Mar. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
3.4
LOWCVE-2025-30163
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (`fromNodes` and `toNodes`) will incorrectly permit traffic to/from non-node endpoints that share the labels specified in `fromNodes` an... Read more
Affected Products : cilium- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
3.2
LOWCVE-2025-30162
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gateway API for Ingress for some services and use LB-IPAM or BGP for LB Service implementation and use network policies to block egress tra... Read more
Affected Products : cilium- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-2749
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be execute... Read more
Affected Products : xperience- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-2748
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.... Read more
Affected Products : xperience- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2747
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.T... Read more
Affected Products : xperience- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2746
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative obj... Read more
Affected Products : xperience- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-2707
A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component Front-End Store Interface. The manipulatio... Read more
- Published: Mar. 24, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-2706
A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted upload. The attack c... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-22223
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using @EnableMethodSecurity, or you do not have method secu... Read more
Affected Products : spring_security- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-30208
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses th... Read more
Affected Products : vite- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-30205
kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause the provisioned a... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Information Disclosure