Latest CVE Feed
-
8.1
HIGHCVE-2025-3834
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.... Read more
Affected Products : manageengine_adaudit_plus- Published: May. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-3833
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.... Read more
Affected Products : manageengine_adselfservice_plus- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-26864
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. ... Read more
Affected Products : iotdb- Published: May. 14, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-26795
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are rec... Read more
Affected Products : iotdb- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-24780
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommend... Read more
Affected Products : iotdb- Published: May. 14, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-2875
CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.... Read more
Affected Products : modicon_m258_firmware modicon_m241_firmware modicon_m251_firmware modicon_lmc058_firmware- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2024-8988
The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it po... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-13940
The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook functionality. This makes it possible for authenticated attackers, with Administrator-level access ... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
6.3
MEDIUMCVE-2024-52290
LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Confi... Read more
Affected Products : ekuiper- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-4520
The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with ... Read more
Affected Products : uncanny_automator- Published: May. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-3623
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticate... Read more
Affected Products : uncanny_automator- Published: May. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-4574
In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.... Read more
Affected Products : crossbeam-channel- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Race Condition
-
5.4
MEDIUMCVE-2025-47905
Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.... Read more
Affected Products : varnish_cache- Published: May. 13, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2025-26646
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.... Read more
Affected Products : linux_kernel macos visual_studio .net windows visual_studio_2022 build_tools_for_visual_studio_2022 build_tools- Published: May. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-43572
Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43571
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43570
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43569
Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-43568
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope... Read more
- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
9.3
CRITICALCVE-2025-43567
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s br... Read more
Affected Products : connect- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting