Latest CVE Feed
-
6.4
MEDIUMCVE-2025-27930
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.... Read more
Affected Products : manageengine_applications_manager- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-53882
A Improper Check for Dropped Privileges vulnerability in the logrotate setup of openSUSE Tumbleweed mailman3 allows the mailman user to create files as root, allowing for a potential privilege escalation. This issue affects openSUSE Tumbleweed: from ? bef... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-41687
An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-41684
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-41683
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test).... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
9.2
CRITICALCVE-2025-8070
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-31701
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices ... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-31700
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices ... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-6174
The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privi... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-54455
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54454
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54453
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54452
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54451
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54450
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54449
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54448
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54447
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54446
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54445
Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Aug. 15, 2025
- Vuln Type: XML External Entity