Latest CVE Feed
-
9.1
CRITICALCVE-2025-23099
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-1051
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. ... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
9.0
CRITICALCVE-2025-5086
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.... Read more
Affected Products : delmia_apriso- Published: Jun. 02, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-45387
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.... Read more
Affected Products : osticket- Published: Jun. 02, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-27956
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.... Read more
Affected Products : weblaudos- Published: Jun. 02, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-27955
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.... Read more
Affected Products : clinical_collaboration_platform- Published: Jun. 02, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-27954
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.... Read more
Affected Products : clinical_collaboration_platform- Published: Jun. 02, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-27953
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.... Read more
Affected Products : clinical_collaboration_platform- Published: Jun. 02, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-23104
An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
- Published: Jun. 02, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
8.0
HIGHCVE-2025-20298
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by d... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-20297
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload ... Read more
- Published: Jun. 02, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-5036
A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the... Read more
Affected Products : revit- Published: Jun. 02, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-48995
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cryptography
-
6.9
MEDIUMCVE-2025-48994
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set (`signxml.XMLVerifier.verify(require_x509=False, hmac_key=...`), versions of SignXML... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Misconfiguration
-
5.2
MEDIUMCVE-2024-8008
A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store connection validation request. A malicious actor can inject a specially crafted pa... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2024-7074
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the ser... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-7073
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate server-side requests, enabling access to internal and ext... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
4.3
MEDIUMCVE-2024-3509
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry section. To exploit this vulnerability, a malicious actor must ha... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-1440
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-48941
MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specifi... Read more
Affected Products : mybb- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization