Latest CVE Feed
-
5.7
MEDIUMCVE-2025-1001
Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modi... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-27100
lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This problem has been... Read more
Affected Products :- Published: Feb. 21, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Denial of Service
-
8.4
HIGHCVE-2025-27088
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to sessio... Read more
Affected Products : s3-proxy- Published: Feb. 20, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-25957
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : xunruicms- Published: Feb. 20, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-25679
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25678
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25676
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.... Read more
- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25675
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the d... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25674
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25668
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25667
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25664
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25663
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25662
Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.... Read more
- Published: Feb. 20, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-22973
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.... Read more
Affected Products : qibocms_x1- Published: Feb. 20, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-54756
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-25960
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-25958
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27098
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerabilit... Read more
- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-27097
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on ... Read more
Affected Products : graphql_mesh- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Misconfiguration