Latest CVE Feed
-
8.5
HIGHCVE-2025-7723
A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-51462
Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-51475
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-51472
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, whi... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-51458
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.edit... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-31513
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-31512
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version eq... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-31511
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20Building%20Access requestSubmit API call. The vendor has stated that the system is protected by updating to a version ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-51479
Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended c... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-51471
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.... Read more
Affected Products : ollama- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-51459
File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hu... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-51464
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48964
ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer ove... Read more
Affected Products : iputils- Published: Jul. 22, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Denial of Service
-
4.5
MEDIUMCVE-2024-38335
IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources.... Read more
- Published: Jul. 22, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-6741
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 202... Read more
Affected Products : devolutions_server- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-6523
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue af... Read more
Affected Products : devolutions_server- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-51482
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intend... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2025-51481
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypa... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Path Traversal
-
9.0
HIGHCVE-2025-8019
A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected by this issue is the function sub_40B6F0 of the file at/appy.cgi. The manipulation of the argument wan_proto leads to buffer overflow. ... Read more
- Published: Jul. 22, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Memory Corruption
-
6.8
MEDIUMCVE-2025-7371
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure