Latest CVE Feed
-
8.7
HIGHCVE-2025-30183
CyberData 011209 Intercom does not properly store or protect web server admin credentials.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-26468
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.... Read more
- Published: Jun. 09, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-5900
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to... Read more
- Published: Jun. 09, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-5899
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not... Read more
Affected Products : pspp- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-5898
A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack nee... Read more
Affected Products : pspp- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-49140
Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be exploited to trigger a panic with Pion based SFU via crafted RTP packets, This only affect use... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-30184
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5897
A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation ... Read more
Affected Products : vue_cli- Published: Jun. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-5896
A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. The manipulation leads to inefficient regular expression complex... Read more
Affected Products : taro- Published: Jun. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-49141
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later pa... Read more
- Published: Jun. 09, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-49139
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the... Read more
- Published: Jun. 09, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-49138
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on t... Read more
- Published: Jun. 09, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-49137
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' ... Read more
- Published: Jun. 09, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-49004
Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on an attacker-controlled domain. This allows a malicious website to hijack the authentication flow of Caido and achiev... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
6.6
MEDIUMCVE-2025-5918
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, incl... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.0
MEDIUMCVE-2025-5917
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corr... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a mali... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-5915
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read b... Read more
- Published: Jun. 09, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5914
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulne... Read more
Affected Products : enterprise_linux openshift_container_platform libarchive libssh international_components_for_unicode- Published: Jun. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5895
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to... Read more
Affected Products : metabase- Published: Jun. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Denial of Service