Latest CVE Feed
-
9.8
CRITICALCVE-2025-50707
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component... Read more
Affected Products : thinkphp- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-50706
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function... Read more
Affected Products : thinkphp- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-47152
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially le... Read more
Affected Products : pdf-xchange_editor- Published: Aug. 05, 2025
- Modified: Aug. 22, 2025
-
5.4
MEDIUMCVE-2025-46958
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
-
3.9
LOWCVE-2025-44964
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.... Read more
Affected Products : bluestacks- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
-
9.3
CRITICALCVE-2025-2611
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
7.5
HIGHCVE-2025-29745
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
6.5
MEDIUMCVE-2025-27931
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the... Read more
Affected Products : pdf-xchange_editor- Published: Aug. 05, 2025
- Modified: Aug. 22, 2025
-
8.4
HIGHCVE-2025-7033
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threa... Read more
Affected Products : arena- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
-
8.4
HIGHCVE-2025-7032
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threa... Read more
Affected Products : arena- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
-
8.4
HIGHCVE-2025-7025
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threa... Read more
Affected Products : arena- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
-
6.1
MEDIUMCVE-2024-52890
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.... Read more
Affected Products : engineering_lifecycle_optimization engineering_lifecycle_optimization_-_publishing- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-54987
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 b... Read more
Affected Products : apex_one- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2025-54948
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.... Read more
Affected Products : apex_one- Actively Exploited
- Published: Aug. 05, 2025
- Modified: Aug. 19, 2025
-
5.1
MEDIUMCVE-2025-8555
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack re... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
4.8
MEDIUMCVE-2025-8554
A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file /admin/user/list. The manipulation of the argument Username leads to cross site scripting. The attack m... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
4.8
MEDIUMCVE-2025-8553
A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code of the file /admin/sensitive_word/list. The manipulation of the argument word leads to cross site scripting. The attack can be initiate... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
4.8
MEDIUMCVE-2025-8552
A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /admin/tag/list. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remot... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
5.1
MEDIUMCVE-2025-8551
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/comment/list. The manipulation of the argument Username leads to cross site scripting. The atta... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
-
6.4
MEDIUMCVE-2025-8295
The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025