Latest CVE Feed
-
8.7
HIGHCVE-2025-34120
An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 151014. The application fails to validate serialized input to the admin backup endpoint (`index.php/admin/update/sa/backup`), allowing a... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-34119
A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. ... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-34118
A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS3000 builds, that allows unauthenticated remote attackers to read arbitrary files on the server. The vulnerability is accessible via mu... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-34117
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-6983
A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into performing unintended actions via rendered UI layers or frames.This issue affects Archer C1200 <= 1.1.5.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.9
MEDIUMCVE-2025-6982
Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), allows attackers to decrypt the config.xml files.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
8.3
HIGHCVE-2025-53908
RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone running the latest version of RomM and has multiple users, even unprivileged user... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-40777
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME c... Read more
Affected Products : bind- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-37107
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.... Read more
Affected Products : autopass_license_server- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-37106
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.... Read more
Affected Products : autopass_license_server- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-37105
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.... Read more
Affected Products : autopass_license_server- Published: Jul. 16, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-36097
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can send a specially crafted request that cause the server to con... Read more
Affected Products : websphere_application_server- Published: Jul. 16, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Denial of Service
-
1.3
LOWCVE-2025-53904
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-20337
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vuln... Read more
- Actively Exploited
- Published: Jul. 16, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
5.8
MEDIUMCVE-2025-20288
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to i... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
4.1
MEDIUMCVE-2025-20285
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is d... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-20284
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied i... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-20283
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied i... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-20274
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-20272
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is du... Read more
- Published: Jul. 16, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Injection