Latest CVE Feed
-
4.8
MEDIUMCVE-2025-4287
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the att... Read more
Affected Products : pytorch- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2025-4286
A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected st... Read more
Affected Products : incontrol_web- Published: May. 05, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-46813
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some conte... Read more
Affected Products : discourse- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-46734
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The ... Read more
Affected Products : commonmark- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-46731
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMI... Read more
Affected Products : craft_cms- Published: May. 05, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-46730
MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal ... Read more
Affected Products : mobile_security_framework- Published: May. 05, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-46726
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with se... Read more
Affected Products : langroid- Published: May. 05, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-45618
Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45617
Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45616
Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45615
Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45614
Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45613
Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45612
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.... Read more
Affected Products : xmall- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-45611
Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45610
Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45609
Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-45608
Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45607
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.... Read more
Affected Products : itranswarp- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1909
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the pl... Read more
Affected Products : buddyboss_platform- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication