Latest CVE Feed
-
6.9
MEDIUMCVE-2025-7745
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
7.8
HIGHCVE-2025-26397
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
9.8
CRITICALCVE-2025-7852
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upl... Read more
Affected Products : wpbookit- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
9.8
CRITICALCVE-2025-7437
The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to up... Read more
Affected Products : ebook_store- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
4.3
MEDIUMCVE-2025-7001
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should hav... Read more
Affected Products : gitlab- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
-
5.3
MEDIUMCVE-2025-4976
An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.... Read more
Affected Products : gitlab- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
-
6.4
MEDIUMCVE-2025-4968
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator With Text, FAQ, Single Image, Custom Header, Button, Call To Action, Pro... Read more
Affected Products : page_builder- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
6.8
MEDIUMCVE-2025-4395
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor model... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
6.8
MEDIUMCVE-2025-4394
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
6.5
MEDIUMCVE-2025-4393
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patien... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
10.0
CRITICALCVE-2025-41240
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A ... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
4.3
MEDIUMCVE-2025-1299
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorize... Read more
Affected Products : gitlab- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
-
4.3
MEDIUMCVE-2025-0765
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.... Read more
Affected Products : gitlab- Published: Jul. 24, 2025
- Modified: Aug. 08, 2025
-
7.8
HIGHCVE-2025-54365
fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of str... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
9.3
CRITICALCVE-2016-15044
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially cr... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
7.8
HIGHCVE-2025-54377
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode does not validate line breaks (\n) in its command input, allowing potential bypass of the allow-list mechanism. The project appears to l... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
7.4
HIGHCVE-2025-53942
authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025.4.4 and earlier, as well as versions 2025.6.0-rc1 through 2025.6.3, deactivated users who registered thro... Read more
Affected Products : authentik- Published: Jul. 23, 2025
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2025-53537
LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, s... Read more
Affected Products : libhtp- Published: Jul. 23, 2025
- Modified: Aug. 05, 2025
-
7.7
HIGHCVE-2025-47281
Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due to improper handling of JMESPath variable substitutions. Attackers with permissions to create... Read more
Affected Products : kyverno- Published: Jul. 23, 2025
- Modified: Aug. 05, 2025
-
4.1
MEDIUMCVE-2025-32019
Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 and 2.13.0-rc1, contain a vulnerability where the markdown field in the info tab page can be ex... Read more
Affected Products : harbor- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025