Latest CVE Feed
-
8.6
HIGHCVE-2025-50850
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passw... Read more
Affected Products : cs-cart- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
-
6.1
MEDIUMCVE-2025-50848
A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload ... Read more
Affected Products : cs-cart- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2025-50847
Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.... Read more
Affected Products : cs-cart- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
-
6.9
MEDIUMCVE-2025-46809
A Insertion of Sensitive Information into Log File vulnerability in SUSE Multi Linux Manager exposes the HTTP proxy credentials. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
7.3
HIGHCVE-2025-29556
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-8408
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /filter1.php. The manipulation of the argument vehicle leads to sql injection. It is possible to launch the a... Read more
- Published: Jul. 31, 2025
- Modified: Aug. 05, 2025
-
8.0
HIGHCVE-2025-52289
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requirin... Read more
Affected Products : magnusbilling- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
-
6.1
MEDIUMCVE-2025-51569
A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html respo... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
8.0
HIGHCVE-2025-50849
CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the se... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-50475
An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary commands as root via crafted input to the hostname parameter in network configuration requests. This vuln... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
6.1
MEDIUMCVE-2025-50270
A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
7.0
HIGHCVE-2025-34146
A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) condition or, under certa... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
5.4
MEDIUMCVE-2025-29557
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
6.3
MEDIUMCVE-2024-34328
An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
9.2
CRITICALCVE-2014-125126
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanis... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
8.8
HIGHCVE-2014-125125
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user inpu... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
10.0
CRITICALCVE-2014-125124
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p paramet... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
10.0
CRITICALCVE-2014-125123
An unauthenticated SQL injection vulnerability exists in the Kloxo web hosting control panel (developed by LXCenter) prior to version 6.1.12. The flaw resides in the login-name parameter passed to lbin/webcommand.php, which fails to properly sanitize inpu... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
5.3
MEDIUMCVE-2014-125122
A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endp... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
-
10.0
CRITICALCVE-2014-125121
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The ... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025