Latest CVE Feed
-
5.5
MEDIUMCVE-2025-2300
Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.... Read more
Affected Products : ops_center_common_services- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2024-46899
Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Ana... Read more
Affected Products : ops_center_common_services- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2025-3577
**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by... Read more
- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
6.7
MEDIUMCVE-2025-1732
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file ... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-1731
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-3856
A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation of the argument sort leads to sql injection. It is possible to initiate the ... Read more
Affected Products : novel-plus- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3855
A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handle... Read more
Affected Products : rise_ultimate_project_manager- Published: Apr. 22, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-3854
A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Req... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-3850
A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated ... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2024-58250
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.... Read more
Affected Products : ppp- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-3849
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack c... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-2987
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.... Read more
Affected Products : maximo_asset_management- Published: Apr. 22, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-3847
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-3846
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file code/http/httprequest.cpp of the component Registration. The manipulation of the argument userna... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-3845
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulnerability is the function Buffer::HasWritten of the file code/buffer/buffer.cpp. The manipulation of the argument writePos_ leads to buff... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-3843
A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed ... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-3842
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of the argument fileUpload leads to code injection. The at... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32958
Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the auto... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Information Disclosure
-
8.0
HIGHCVE-2025-32956
ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQL injection when renaming a namespace in Special:ManageWiki/namespaces when using a page prefix (namespace name, which is the current n... Read more
Affected Products : managewiki- Published: Apr. 21, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2025-32955
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `disable-sudo` bypass. Harden-Runner includes a policy option `disable-sudo` to prevent the GitHub Actions r... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration