Latest CVE Feed
-
8.8
HIGHCVE-2025-8701
A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /OL_OprationLog/GetPageList. The manipulation of the argument optU... Read more
Affected Products : woes_intelligent_optimization_energy_saving_system- Published: Aug. 07, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-8698
A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of the component AMF Service. The manipulation leads to reac... Read more
Affected Products : open5gs- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-53792
Azure Portal Elevation of Privilege Vulnerability... Read more
Affected Products : azure_portal- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
8.2
HIGH- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGH- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICAL- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-45765
ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cryptography
-
7.0
HIGHCVE-2025-26513
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-48709
An issue was discovered in BMC Control-M 9.0.21.300. When Control-M Server has a database connection, it runs DBUStatus.exe frequently, which then calls dbu_connection_details.vbs with the username, password, database hostname, and port written in clearte... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
5.6
MEDIUMCVE-2025-47808
In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-47807
In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2025-47806
In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
8.1
HIGHCVE-2025-47219
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-47183
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.... Read more
Affected Products : gstreamer- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-8697
A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation leads to os command injection. The attack may... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
5.2
MEDIUMCVE-2025-7195
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
7.4
HIGHCVE-2025-55077
Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deploy... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-51533
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-50692
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.... Read more
Affected Products : foxcms- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-50675
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration