Latest CVE Feed
-
8.8
HIGHCVE-2025-28237
An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28236
Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-28235
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-28233
Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract ses... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
-
9.1
CRITICALCVE-2025-28231
Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
-
6.9
MEDIUMCVE-2025-1697
A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing s... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-28059
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails ... Read more
Affected Products : network_analyzer- Published: Apr. 18, 2025
- Modified: Jul. 11, 2025
-
5.4
MEDIUMCVE-2024-41447
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.... Read more
Affected Products : opencms- Published: Apr. 18, 2025
- Modified: Apr. 23, 2025
-
6.5
MEDIUMCVE-2025-32796
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal us... Read more
Affected Products : dify- Published: Apr. 18, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-32795
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-a... Read more
Affected Products : dify- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-32792
SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web extensions using `ses` and the Compartment API to evaluate third-party code i... Read more
Affected Products : ses- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
-
7.5
HIGHCVE-2025-32442
Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for different content types have a possibility to bypass validation by providing... Read more
Affected Products : fastify- Published: Apr. 18, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-32434
PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loa... Read more
Affected Products : pytorch- Published: Apr. 18, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-32389
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refe... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-31120
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-31118
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously p... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-30357
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
-
7.1
HIGHCVE-2025-30158
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attribut... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-29953
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deseriali... Read more
Affected Products : activemq_nms_openwire- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-29784
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search q... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service