Latest CVE Feed
-
8.8
HIGHCVE-2025-9153
A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument photo results in unrestricted upload. The att... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
9.3
CRITICALCVE-2025-55736
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
-
5.4
MEDIUMCVE-2025-55735
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe ... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
-
6.9
MEDIUMCVE-2025-55734
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when ... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
-
9.6
CRITICALCVE-2025-55733
DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any we... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-55306
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could ... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.9
MEDIUMCVE-2025-55303
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2025-52338
An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-50891
Adform Site Tracking 1.1 allows attackers to inject HTML or execute arbitrary code via cookie hijacking.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.9
MEDIUMCVE-2025-43745
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.1... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
5.1
MEDIUMCVE-2025-43737
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_po... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
5.4
MEDIUMCVE-2025-33008
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
4.9
MEDIUMCVE-2025-31988
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.... Read more
Affected Products : digital_experience- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-44373
A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-9151
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of the file /web_config/json/name/web. Performing manipulation results in improper authorization. It is possi... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2025-9150
A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. Such manipulation of the argument ID leads to sql injection. The ... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-9149
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out rem... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
8.2
HIGHCVE-2025-8450
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.... Read more
Affected Products : filecatalyst_direct- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-55295
qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web API that allows authenticated users to read arbitrary files from the server filesystem through the restore_c... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-55294
screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command withou... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025