Latest CVE Feed
-
4.3
MEDIUMCVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-48746
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.... Read more
Affected Products : directory_manager- Published: May. 28, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-36572
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vul... Read more
Affected Products : powerstoreos powerstore_500t powerstore_1000t powerstore_1200t powerstore_3200t powerstore_3000t powerstore_5200t powerstore_5000t powerstore_7000t powerstore_9000t +2 more products- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecur... Read more
Affected Products : kea- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-32801
Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea ver... Read more
Affected Products : kea- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
5.1
MEDIUMCVE-2024-47056
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead to the disclosure of sensitive information, including database credentials, A... Read more
Affected Products : mautic- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-45343
An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.... Read more
- Published: May. 28, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-51453
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.... Read more
Affected Products : sterling_secure_proxy- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-38341
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
Affected Products : sterling_secure_proxy- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-3357
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array.... Read more
Affected Products : tivoli_monitoring- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.6
CRITICALCVE-2025-5277
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
-
7.3
HIGHCVE-2025-4134
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2025-48734
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. Howev... Read more
Affected Products : commons_beanutils- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2025-45997
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.... Read more
Affected Products : web-based_pharmacy_product_management_system- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Misconfiguration
-
5.1
MEDIUMCVE-2025-40651
Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This ... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-4493
Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Ser... Read more
Affected Products : devolutions_server- Published: May. 28, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-5299
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation of the argument uploaded_file_cancel... Read more
- Published: May. 28, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-5298
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to ... Read more
Affected Products : online_hospital_management_system- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2025-5297
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer... Read more
Affected Products : simple_computer_store_system- Published: May. 28, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Memory Corruption
-
2.3
LOWCVE-2025-3864
Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, causing denial of service in applications using the library. Fix for this issue ... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service