Latest CVE Feed
-
6.8
MEDIUMCVE-2024-12086
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums... Read more
Affected Products : enterprise_linux openshift_container_platform rsync suse_linux linux nixos arch_linux smartos almalinux- Published: Jan. 14, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-12085
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uniniti... Read more
Affected Products : enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus openshift_container_platform enterprise_linux_eus openshift enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus +13 more products- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-23081
Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Cross Site Request Forgery, Cross-Site Scripting... Read more
Affected Products : mediawiki- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-23080
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-0464
A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Section. The manipulation of the argument System Name leads ... Read more
- Published: Jan. 14, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-0463
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minip... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0462
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&min... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-53563
A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2024-53561
A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 31, 2025
-
6.2
MEDIUMCVE-2024-52898
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.... Read more
- Published: Jan. 14, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
5.9
MEDIUMCVE-2024-45627
In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, th... Read more
Affected Products : linkis- Published: Jan. 14, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-13181
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.... Read more
Affected Products : avalanche- Published: Jan. 14, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-13180
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.... Read more
Affected Products : avalanche- Published: Jan. 14, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-13179
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.... Read more
Affected Products : avalanche- Published: Jan. 14, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-10811
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2024-10630
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.... Read more
- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2025-22984
An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.... Read more
Affected Products : icecms- Published: Jan. 14, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-22983
An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.... Read more
Affected Products : icecms- Published: Jan. 14, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-0461
A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAja... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-0460
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Authentication