Latest CVE Feed
-
6.9
MEDIUMCVE-2025-57788
An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2025-8289
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenti... Read more
Affected Products : redirection_for_contact_form_7- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.8
HIGHCVE-2025-8145
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated at... Read more
Affected Products : redirection_for_contact_form_7- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.8
HIGHCVE-2025-8141
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unaut... Read more
Affected Products : redirection_for_contact_form_7- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
6.9
MEDIUMCVE-2025-54364
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracki... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
-
6.9
MEDIUMCVE-2025-54363
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastr... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
-
8.8
HIGHCVE-2025-9132
Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
-
9.3
CRITICALCVE-2024-12223
Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.1
MEDIUMCVE-2025-9193
A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to open redirect. The attack may be performed from a remote lo... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2025-9176
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local ac... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2025-9175
A vulnerability was identified in neurobin shc up to 4.0.3. This issue affects the function make of the file src/shc.c. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit is public... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2025-9174
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the function make of the file src/shc.c of the component Filename Handler. Executing manipulation can lead to os command injection. The attack can only be executed loca... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
5.4
MEDIUMCVE-2025-9171
A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is ... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
5.4
MEDIUMCVE-2025-9170
A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be execu... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
5.4
MEDIUMCVE-2025-9169
A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possibl... Read more
Affected Products : solidinvoice- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-9187
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-9186
Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
8.1
HIGHCVE-2025-9185
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enoug... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
8.1
HIGHCVE-2025-9184
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2025-9183
Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2.... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025