Latest CVE Feed
-
4.8
MEDIUMCVE-2025-5543
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-24015
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in Deno in which the authentication tag is not being validated. This means tampered ciphertexts or incorrect ke... Read more
Affected Products : deno- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2025-5542
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type le... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-5527
A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer o... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-49002
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohi... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49001
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10.... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2025-49000
InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticate... Read more
Affected Products : inventree- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-48999
DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, ... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-48951
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, ... Read more
Affected Products : auth0- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-5525
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be... Read more
Affected Products : trojan- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-5523
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of t... Read more
Affected Products : web-flash- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-35036
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute ar... Read more
Affected Products :- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-23100
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-23098
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
Affected Products : exynos_980_firmware exynos_1080_firmware exynos_2100_firmware exynos_2200_firmware exynos_1280_firmware exynos_1380_firmware exynos_980 exynos_990_firmware exynos_990 exynos_1080 +4 more products- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-23097
An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5522
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The... Read more
Affected Products :- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-5521
A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site request forgery. The... Read more
Affected Products : wukongcrm- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-48998
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The ... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-48997
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an... Read more
Affected Products :- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-48953
Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with the configured allowable file extensions via a manipulated API request. The ... Read more
Affected Products : umbraco_cms- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration