Latest CVE Feed
-
5.4
MEDIUMCVE-2025-2950
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-29625
A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an overly long environment variable passed to FileOpen function.... Read more
Affected Products : astrolog- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29209
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.... Read more
- Published: Apr. 18, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-28232
Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-28230
Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28229
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-28228
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.... Read more
Affected Products : fm\/dab\/tv_transmitter_web_management_system- Published: Apr. 18, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-29643
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.... Read more
Affected Products : croogo- Published: Apr. 18, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-40364
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if ne... Read more
Affected Products : linux_kernel- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
-
6.9
MEDIUMCVE-2025-3790
A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache Druid Monitoring Console. The manipulation leads to improper access controls. It is possible to ... Read more
Affected Products : jsite- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-3789
A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a/sys/area/save. The manipulation of the argument Name leads to cross site scripting. The attack may be lau... Read more
Affected Products : jsite- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-32790
Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrat... Read more
Affected Products : dify- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2024-46089
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.... Read more
Affected Products : 74cms- Published: Apr. 18, 2025
- Modified: May. 28, 2025
-
6.5
MEDIUMCVE-2024-49808
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-45651
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-3788
A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /a/sys/user/save. The manipulation of the argument Name leads to cross site scripting. The attack c... Read more
Affected Products : jsite- Published: Apr. 18, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-3787
A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The ex... Read more
Affected Products : pbootcms- Published: Apr. 18, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
6.4
MEDIUMCVE-2025-3106
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on u... Read more
Affected Products : element_kit_for_elementor- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-3786
A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be ... Read more
- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-3785
A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to st... Read more
- Published: Apr. 18, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication