Latest CVE Feed
-
7.8
HIGHCVE-2025-49157
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on t... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-49156
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target ... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-49155
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-49154
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of aff... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-34511
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server u... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-34510
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by sending a crafted ... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
8.2
HIGHCVE-2025-34509
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote at... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49220
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different me... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49219
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different m... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-47867
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-47866
An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations.... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-47865
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-33122
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.... Read more
- Published: Jun. 17, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-45880
A cross-site scripting (XSS) vulnerability in the data resource management function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.... Read more
Affected Products : amygdala- Published: Jun. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-45878
A cross-site scripting (XSS) vulnerability in the report manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.... Read more
Affected Products : amygdala- Published: Jun. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-45879
A cross-site scripting (XSS) vulnerability in the e-mail manager function of Miliaris Amigdala v2.2.6 allows attackers to execute arbitrary HTML in the context of a user's browser via a crafted payload.... Read more
Affected Products : amygdala- Published: Jun. 17, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.3
LOWCVE-2025-6199
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-6196
A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected ... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
2.3
LOWCVE-2025-4754
Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex. This issue affects ash_authentication_phoe... Read more
Affected Products : ash_authentication_phoenix- Published: Jun. 17, 2025
- Modified: Jul. 04, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-49882
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emraan Cheema CubeWP Framework allows DOM-Based XSS. This issue affects CubeWP Framework: from n/a through 1.1.23.... Read more
Affected Products : cubewp- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting