Latest CVE Feed
-
0.0
NONECVE-2025-48938
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2025-48885
application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can create these docs, even if they don't exist already. This can... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2025-48883
Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. ... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.3
CVSS31CVE-2025-5358
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/tod... Read more
Affected Products : cyber_cafe_management_system- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.3
CVSS31CVE-2025-5357
A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PWD Command Handler. The manipulation leads to buffer overflow. The attack can be launched... Read more
Affected Products : freefloat_ftp_server- Published: May. 30, 2025
- Modified: May. 30, 2025
-
4.7
CVSS31CVE-2025-5054
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crash... Read more
Affected Products : apport- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2025-48887
vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file `vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py` of versions 0.6.4 up to but excluding 0.9.0... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2023-26226
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682... Read more
Affected Products : yandex_browser- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.3
CVSS31CVE-2025-5356
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The e... Read more
Affected Products : freefloat_ftp_server- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2024-42191
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2024-42190
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.8
CVSS31CVE-2024-23589
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2024-13917
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious applic... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2024-13916
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ con... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2024-13915
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4992
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser ses... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4991
A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4990
A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4989
A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4988
A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's bro... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025