Latest CVE Feed
-
6.5
MEDIUMCVE-2025-27100
lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This problem has been... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Denial of Service
-
8.4
HIGHCVE-2025-27088
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to sessio... Read more
Affected Products : s3-proxy- Published: Feb. 20, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-25957
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : xunruicms- Published: Feb. 20, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-25679
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25678
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25676
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25675
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the d... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25674
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25668
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25667
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25664
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25663
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25662
Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.... Read more
- Published: Feb. 20, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-22973
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.... Read more
Affected Products : qibocms_x1- Published: Feb. 20, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-54756
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-25960
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-25958
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27098
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerabilit... Read more
- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-27097
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on ... Read more
Affected Products : graphql_mesh- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Misconfiguration
-
2.3
LOWCVE-2025-25299
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. This vulnerability affects user marke... Read more
Affected Products : ckeditor5- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Cross-Site Scripting