Latest CVE Feed
-
8.8
HIGHCVE-2024-23968
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToS... Read more
- Published: Jan. 31, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
8.0
HIGHCVE-2024-23963
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit thi... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2024-23962
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens... Read more
- Published: Jan. 31, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-23937
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. ... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-23930
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Med... Read more
- Published: Jan. 31, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2024-23928
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists ... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-1211
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab ins... Read more
Affected Products : gitlab- Published: Jan. 31, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-6195
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker u... Read more
Affected Products : gitlab- Published: Jan. 31, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
7.7
HIGHCVE-2025-24886
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a ... Read more
Affected Products :- Published: Jan. 30, 2025
- Modified: Jan. 30, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2025-24885
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.... Read more
Affected Products :- Published: Jan. 30, 2025
- Modified: Jan. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-0882
A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/addnewmember.php. The manipulation of the argument user leads to sql injection... Read more
- Published: Jan. 30, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0881
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. The manipulation of the argument rname leads to sql injection. It is possibl... Read more
- Published: Jan. 30, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0880
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The manipulation of the argument planid leads to sql injection. The attack ... Read more
- Published: Jan. 30, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-0574
Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-0573
Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is not required to exploit this ... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-0572
Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is required to exploi... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-0571
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required ... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0570
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required ... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-0569
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to expl... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-0568
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to expl... Read more
Affected Products : sante_pacs_server- Published: Jan. 30, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Memory Corruption