Latest CVE Feed
-
4.7
MEDIUMCVE-2022-28693
Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2022-26083
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cryptography
-
6.9
MEDIUMCVE-2025-25304
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to version 5.26.0 of vega and 5.4.2 of vega-selections, the `vlSelectionTuples` function can be used to call JavaScript functi... Read more
Affected Products : vega- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-25297
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, th... Read more
Affected Products : label_studio- Published: Feb. 14, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2025-25296
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appropriately crafted `label_config` query parameter. By craf... Read more
Affected Products : label_studio- Published: Feb. 14, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-25290
@octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to version 9.2.1, the regular expression `/<([^>]+)>; rel="deprecation"/` used to match the `link` header in HT... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-25289
@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authori... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-25288
@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially cra... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-25285
@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Denial of Service
-
3.1
LOWCVE-2025-0503
Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker to infer user IDs and other metadata from deleted DMs if someone had manually marked DMs as deleted in the database.... Read more
- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Information Disclosure
-
8.3
HIGHCVE-2025-26508
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-26507
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Misconfiguration
-
9.2
CRITICALCVE-2025-26506
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Misconfiguration
-
5.6
MEDIUMCVE-2025-26158
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.... Read more
Affected Products : online_attendance_management_system- Published: Feb. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-26157
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.... Read more
Affected Products : beauty_parlour_management_system- Published: Feb. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-26156
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.... Read more
- Published: Feb. 14, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-25997
Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 13, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-25994
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-25993
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-25992
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection