Latest CVE Feed
-
5.8
MEDIUMCVE-2025-52967
gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.... Read more
Affected Products : mlflow- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2025-52879
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible... Read more
Affected Products : teamcity- Published: Jun. 23, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-52878
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions... Read more
Affected Products : teamcity- Published: Jun. 23, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2025-52877
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible... Read more
Affected Products : teamcity- Published: Jun. 23, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-52876
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible... Read more
Affected Products : teamcity- Published: Jun. 23, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-52875
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible... Read more
Affected Products : teamcity- Published: Jun. 23, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-48700
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to ... Read more
Affected Products : zimbra_collaboration_suite- Published: Jun. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-46101
SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-48978
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.... Read more
Affected Products : itm_web_terminal- Published: Jun. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2023-47298
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account status... Read more
Affected Products : terminal_handler- Published: Jun. 23, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2023-47297
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.... Read more
Affected Products : terminal_handler- Published: Jun. 23, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
6.6
MEDIUMCVE-2025-2172
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames... Read more
Affected Products : controller- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-2171
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN... Read more
Affected Products : controller- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-6513
Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICALCVE-2025-6512
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-52922
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2025-52921
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Functio... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-52920
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers a... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-23049
Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-52939
Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption