Latest CVE Feed
-
9.8
CRITICALCVE-2025-25674
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25668
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25667
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25664
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25663
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25662
Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.... Read more
- Published: Feb. 20, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-22973
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.... Read more
Affected Products : qibocms_x1- Published: Feb. 20, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-54756
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-25960
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-25958
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.... Read more
Affected Products : phpcms- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27098
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerabilit... Read more
- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-27097
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on ... Read more
Affected Products : graphql_mesh- Published: Feb. 20, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Misconfiguration
-
2.3
LOWCVE-2025-25299
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. During a recent internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 real-time collaboration package. This vulnerability affects user marke... Read more
Affected Products : ckeditor5- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-24893
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability ... Read more
Affected Products : xwiki- Published: Feb. 20, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-1265
An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-0352
Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-27096
WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQ... Read more
Affected Products : wegia- Published: Feb. 20, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
7.0
HIGHCVE-2025-26618
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use comp... Read more
Affected Products : otp- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Denial of Service
-
5.9
MEDIUMCVE-2024-7141
Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2023-51339
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e... Read more
Affected Products : event_ticketing_system- Published: Feb. 20, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Denial of Service