Latest CVE Feed
-
9.8
CRITICALCVE-2025-2776
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Actively Exploited
- Published: May. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: XML External Entity
-
9.3
CRITICALCVE-2025-2775
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products : sysaid- Actively Exploited
- Published: May. 07, 2025
- Modified: Jul. 23, 2025
- Vuln Type: XML External Entity
-
7.5
HIGHCVE-2025-29448
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.... Read more
- Published: May. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-29602
flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.... Read more
Affected Products : flatpress- Published: May. 07, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29154
HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspecti... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-29153
SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.... Read more
Affected Products : galera- Published: May. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
7.6
HIGHCVE-2025-29152
Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Reg... Read more
Affected Products : galera- Published: May. 07, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2020-36791
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_all... Read more
Affected Products : linux_kernel- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-33093
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.... Read more
Affected Products : sterling_partner_engagement_manager- Published: May. 07, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4104
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset t... Read more
Affected Products : frontend_dashboard- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-39361
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.... Read more
Affected Products : royal_elementor_addons- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27533
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denia... Read more
Affected Products : activemq- Published: May. 07, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Denial of Service
-
4.0
MEDIUMCVE-2025-20980
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2025-20979
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-20978
Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.... Read more
Affected Products : penup- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-20977
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.... Read more
Affected Products : notes- Published: May. 07, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-20976
Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.... Read more
Affected Products : notes- Published: May. 07, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-20975
Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-20974
Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-20973
Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication