Latest CVE Feed
-
6.9
MEDIUMCVE-2025-5511
A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. The attack may be ... Read more
Affected Products : shiyi-blog- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-5510
A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of the argument url leads to server-side request forgery. The attack can... Read more
Affected Products : shiyi-blog- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-32106
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32105
A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-30167
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_... Read more
Affected Products : jupyter_core- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-23107
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5509
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the att... Read more
Affected Products : shiyi-blog- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2025-5508
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment leads to cross sit... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-5507
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cros... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-45854
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.... Read more
Affected Products : jehc-bpm- Published: Jun. 03, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44148
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component... Read more
Affected Products : mailenable- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-25022
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.... Read more
- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-25021
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.... Read more
- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-25020
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.... Read more
- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-25019
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.... Read more
- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2025-23103
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2025-1334
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Jun. 03, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-5506
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scripting. It is pos... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5505
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-5504
A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the argument peerRptPin leads to command injection. The attack can ... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection