Latest CVE Feed
-
8.8
HIGHCVE-2025-0975
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.... Read more
- Published: Feb. 28, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-0823
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary fi... Read more
Affected Products : cognos_analytics- Published: Feb. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-56340
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.... Read more
Affected Products : cognos_analytics- Published: Feb. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
4.7
MEDIUMCVE-2024-54173
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.... Read more
- Published: Feb. 28, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-25729
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-25728
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cryptography
-
6.2
MEDIUMCVE-2025-25727
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2025-25477
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-1687
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to u... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-1682
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level acce... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-1681
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-12811
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and abo... Read more
Affected Products : traveler- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-24832
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) befo... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-37567
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-37566
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-36047
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-36046
Infoblox NIOS through 8.6.4 executes with more privileges than required.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26325
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.... Read more
Affected Products : shopxo- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
8.8
HIGHCVE-2025-26264
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-25730
An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Misconfiguration