Latest CVE Feed
-
8.7
HIGHCVE-2025-54125
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, th... Read more
Affected Products : xwiki- Published: Aug. 06, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2025-54124
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1... Read more
Affected Products : xwiki- Published: Aug. 06, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-32430
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabil... Read more
Affected Products : xwiki- Published: Aug. 06, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-8573
Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concr... Read more
- Published: Aug. 05, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-8571
Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection ... Read more
- Published: Aug. 05, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-53534
RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-52237
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.... Read more
Affected Products : sscms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-52078
File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-51541
A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before rendering it in the browser, ... Read more
Affected Products : shopware- Published: Aug. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-50592
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.... Read more
Affected Products : seacms- Published: Aug. 05, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2014-125113
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2013-10070
PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that injects arbitrary... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2013-10069
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker c... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2013-10068
Foxit Reader Plugin version 2.2.1.530, bundled with Foxit Reader 5.4.4.11281, contains a stack-based buffer overflow vulnerability in the npFoxitReaderPlugin.dll module. When a PDF file is loaded from a remote host, an overly long query string in the URL ... Read more
Affected Products : pdf_reader- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Memory Corruption
-
9.4
CRITICALCVE-2013-10067
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2013-10066
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) that allows attackers to upload files to the /userpictures/ directory without authentication. This flaw ena... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2013-10065
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
9.3
CRITICALCVE-2013-10064
A stack-based buffer overflow vulnerability exists in ActFax Server version 5.01. The server's RAW protocol interface fails to safely process user-supplied data in @F506 fax header fields due to insecure usage of strcpy. Remote attackers can exploit this ... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2012-10035
Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary c... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
8.7
HIGHCVE-2012-10034
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outsi... Read more
Affected Products :- Published: Aug. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal