Latest CVE Feed
-
6.5
MEDIUMCVE-2025-49463
Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.... Read more
Affected Products : zoom- Published: Jul. 10, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
3.5
LOWCVE-2025-49462
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.... Read more
Affected Products : zoom- Published: Jul. 10, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-47813
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.... Read more
Affected Products : wing_ftp_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICALCVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP serv... Read more
Affected Products : wing_ftp_server- Actively Exploited
- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2025-47811
In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web application itself offers several legitimate ways to execute arbitrary system commands (i.e., through the web... Read more
Affected Products : wing_ftp_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-27889
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.... Read more
Affected Products : wing_ftp_server- Published: Jul. 10, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-23048
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, wi... Read more
Affected Products : http_server- Published: Jul. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-47252
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with ... Read more
Affected Products : http_server- Published: Jul. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-43394
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-43204
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response hea... Read more
Affected Products : http_server- Published: Jul. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-42516
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38... Read more
Affected Products : http_server- Published: Jul. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-6395
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-53364
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a s... Read more
Affected Products : parse-server- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-46789
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.... Read more
Affected Products : zoom- Published: Jul. 10, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-46788
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.... Read more
Affected Products : workplace_desktop- Published: Jul. 10, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-7408
A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/templates/animal_form_template.php. The manipulation of the argument msg leads to cross si... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-7365
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability a... Read more
- Published: Jul. 10, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
8.5
HIGHCVE-2025-46835
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite fi... Read more
Affected Products : git- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-46334
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when ... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-44251
Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Misconfiguration