Latest CVE Feed
-
4.3
MEDIUMCVE-2025-49543
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.2
MEDIUMCVE-2025-49542
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript c... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-49541
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-49540
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2025-49539
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerab... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: XML External Entity
-
7.4
HIGHCVE-2025-49538
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized file... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: XML External Entity
-
7.9
HIGHCVE-2025-49537
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged attacker.... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-49536
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and g... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-49535
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access ... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: XML External Entity
-
5.5
MEDIUMCVE-2025-43584
Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.... Read more
Affected Products : substance_3d_viewer- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-43583
Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service.... Read more
Affected Products : substance_3d_viewer- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-43582
Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user, scope unchanged. Exploitation of this issue requires user interacti... Read more
Affected Products : substance_3d_viewer- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7193
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/suppliercontroller.php. The manipulation of the argument supplier leads to sql ... Read more
Affected Products : agri-trading_online_shopping_system- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7192
A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiate... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-53355
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes MCP Server. The vulnerability is caused by the unsanitized use of input parameters within ... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37103
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the ... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-7191
A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be i... Read more
Affected Products : student_enrollment- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7190
A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is... Read more
Affected Products : library_management_system- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-48386
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The wincred credential helper uses a static buffer (target) as a unique key for storing ... Read more
Affected Products : git- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Memory Corruption
-
8.6
HIGHCVE-2025-48385
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remot... Read more
Affected Products : git- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration