Latest CVE Feed
-
7.8
HIGHCVE-2024-9157
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID ... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-56338
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended... Read more
Affected Products : sterling_b2b_integrator- Published: Mar. 11, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-27617
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.... Read more
Affected Products : pimcore- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2025-27602
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or... Read more
Affected Products : umbraco_cms- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-27601
Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and upda... Read more
Affected Products : umbraco_cms- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-25747
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint... Read more
Affected Products : hoteldruid- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-25680
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially cra... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-27403
Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security metadata and admits for deployment only those that comply with policies the user creates. In a Kubernetes environment, Ratify can be c... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-22454
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : secure_access_client- Published: Mar. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-55597
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests.... Read more
Affected Products : fortiweb- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Path Traversal
-
3.8
LOWCVE-2024-55592
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all ver... Read more
Affected Products : fortisiem- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-55590
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission an... Read more
Affected Products : fortiisolator- Published: Mar. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-54026
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23.4, FortiSandbox at least 4.4.0 through 4.4.6 and 4.2.0 through 4.2.7 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2024-54018
Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.... Read more
Affected Products : fortisandbox- Published: Mar. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-52961
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.7, 4.2.0 through 4.2.7 and before 4.0.5 allows an authenticated attacker with at least read-only permissi... Read more
Affected Products : fortisandbox- Published: Mar. 11, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-52960
A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via... Read more
Affected Products : fortisandbox- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-51322
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2024-51321
In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-51320
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-51319
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Path Traversal