Latest CVE Feed
-
7.7
HIGHCVE-2025-46568
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, e... Read more
Affected Products : stirling_pdf- Published: May. 01, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Server-Side Request Forgery
-
7.8
HIGHCVE-2025-46567
LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on use... Read more
Affected Products : llama-factory- Published: May. 01, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-46566
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.... Read more
Affected Products : dataease- Published: May. 01, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
6.0
MEDIUMCVE-2025-46565
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly expos... Read more
Affected Products : vite- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-46345
Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user informatio... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-46337
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using A... Read more
Affected Products : adodb- Published: May. 01, 2025
- Modified: May. 26, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44867
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44866
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44865
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44864
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44863
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44862
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-44861
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44860
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: May. 01, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-32890
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the messa... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-32889
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app.... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-32888
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cryptography
-
7.1
HIGHCVE-2025-32887
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopping.... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-32886
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-32885
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the... Read more
- Published: May. 01, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Misconfiguration