Latest CVE Feed
-
6.6
MEDIUMCVE-2025-2172
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames... Read more
Affected Products : controller- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-2171
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN... Read more
Affected Products : controller- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-6513
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICALCVE-2025-6512
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-52922
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2025-52921
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Functio... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-52920
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers a... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-23049
Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-52939
Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-52938
Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: through v0.11. The singlevar() in lparser.c lacks a certain luaK_exp2anyregup... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2025-52937
Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
-
9.3
CRITICALCVE-2025-52936
Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-52935
Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18.... Read more
Affected Products : dragonfly- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
7.4
HIGHCVE-2025-27387
OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.... Read more
Affected Products : coloros- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
9.6
CRITICALCVE-2024-45347
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-3511
An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, a malicious actor with access to the management console can exploit a s... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6503
A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. The manipulation of the argument categoriesId leads to s... Read more
Affected Products : inventory_management_system- Published: Jun. 23, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6502
A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection... Read more
Affected Products : inventory_management_system- Published: Jun. 23, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6501
A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/createCategories.php. The manipulation of the argument categoriesStatus leads to sql inject... Read more
Affected Products : inventory_management_system- Published: Jun. 23, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6500
A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCategories.php. The manipulation of the argument editCateg... Read more
Affected Products : inventory_management_system- Published: Jun. 23, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection