Latest CVE Feed
-
2.6
LOWCVE-2025-55285
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly... Read more
Affected Products : backstage- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-9060
A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerabili... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-8996
Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.... Read more
Affected Products : layout_builder_advanced_permissions- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-8995
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.... Read more
Affected Products : authenticator_login- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-8675
Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6.... Read more
Affected Products : ai_seo_link_advisor- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2025-8362
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.... Read more
Affected Products : googletag_manager- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-8361
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.This issue affects Config Pages: from 0.0.0 before 2.18.0.... Read more
Affected Products : config_pages- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
7.6
HIGHCVE-2025-8092
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.16.... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-7961
Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This issue affects KAP: 3.6.0.... Read more
Affected Products : kap- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-8066
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This issue affects Bunker Web: 1.6.2.... Read more
Affected Products : bunker_web- Published: Aug. 15, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-55207
Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https://example.com//... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-49898
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix allows DOM-Based XSS.This issue affects Dropshix: from n/a through 4.0.14.... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-49897
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blind SQL Injection. This issue affects Vertical scroll slideshow gallery v2: from n/a through 9.1.... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-49432
Missing Authorization vulnerability in FWDesign Ultimate Video Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Video Player: from n/a through 10.1.... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-5048
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5047
A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of t... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5046
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-55203
Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerability exists in the description_html field of Plane. This flaw allows an attacker to inject malicious JavaScript code that is stored and... Read more
Affected Products : plane- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-54989
Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr message from client. I... Read more
Affected Products : firebird- Published: Aug. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-54466
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can explo... Read more
Affected Products : ofbiz- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection