Latest CVE Feed
-
5.1
MEDIUMCVE-2025-2327
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure
-
2.5
LOWCVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow atta... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-6129
A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url... Read more
- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6128
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url lead... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-49796
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-49795
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.... Read more
- Published: Jun. 16, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-49794
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious ... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-6127
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search-report.php. The manipulation of the argument serachdata leads to ... Read more
Affected Products : nipah_virus_testing_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6126
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site sc... Read more
Affected Products : rail_pass_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
8.2
HIGHCVE-2025-4565
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This ca... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-49125
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. Tha... Read more
Affected Products : tomcat- Published: Jun. 16, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2025-49124
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0... Read more
Affected Products : tomcat- Published: Jun. 16, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-48988
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the ti... Read more
Affected Products : tomcat- Published: Jun. 16, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-48976
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to u... Read more
Affected Products : commons_fileupload- Published: Jun. 16, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Denial of Service
-
8.6
HIGHCVE-2025-3594
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary l... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2025-3526
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-6125
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is p... Read more
Affected Products : rail_pass_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6124
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipulation of the argument ID leads to sql injection. The attack may be initiate... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-3602
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to ... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-36632
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization