Latest CVE Feed
-
5.1
MEDIUMCVE-2025-25991
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.... Read more
Affected Products : hoosk- Published: Feb. 14, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-25990
Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.... Read more
Affected Products : hoosk- Published: Feb. 14, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-25988
Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.... Read more
Affected Products : hoosk- Published: Feb. 14, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-25295
Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export funct... Read more
Affected Products : label_studio- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-25206
eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. Thi... Read more
Affected Products : elabftw- Published: Feb. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
6.3
MEDIUMCVE-2025-25204
`gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation cli tool `gh attestation verify` causes it to return a zero exit status when no attestati... Read more
Affected Products : cli- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Misconfiguration
-
7.3
HIGHCVE-2024-8893
Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wi‑Fi.This issue affects GW1500‑XS: 1.1.2.1.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-57790
IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically proximate attackers to gain root access via UART or SSH.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2024-56463
IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
2.3
LOWCVE-2024-3220
There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file locations are writable meaning other users can create invalid files to cause MemoryError to be raised on Python runtime startup or have fi... Read more
Affected Products : python- Published: Feb. 14, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-25745
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetQuickVPNSettings module.... Read more
- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-57778
An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-57725
An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-56973
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-25740
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSettings module.... Read more
- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-56477
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.... Read more
Affected Products : power_hardware_management_console- Published: Feb. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-52895
IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of ... Read more
- Published: Feb. 14, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-1239
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the Blocked Sites list. This vulnerability requires an authenticated administrator session to a local... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-1071
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a local... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-0178
Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, pois... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting