Latest CVE Feed
-
8.5
HIGHCVE-2025-3618
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on th... Read more
Affected Products : thinmanager- Published: Apr. 15, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Denial of Service
-
8.5
HIGHCVE-2025-3617
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. ... Read more
Affected Products : thinmanager- Published: Apr. 15, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-33028
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User intera... Read more
Affected Products : winzip- Published: Apr. 15, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-33027
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this... Read more
Affected Products : bandizip- Published: Apr. 15, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-33026
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerabili... Read more
Affected Products : peazip- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-29705
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.... Read more
Affected Products : code-gen- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28100
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.... Read more
Affected Products : dingfanzu- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2024-50960
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the unde... Read more
Affected Products : smp_111_firmware smp_111 smp_351_firmware smp_351 smp_352_firmware smp_352 smp_211_firmware smp_211 sme_211_firmware sme_211- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-42200
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2024-42189
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2021-27289
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is im... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-32780
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\... Read more
Affected Products : bleachbit- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-32779
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to the `/backup/import` API endpoint can write arbitrary files to locations outside the intended extraction di... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-32776
OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attacker can cause the custom kernel driver to read more byt... Read more
Affected Products : openrazer- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Memory Corruption
-
5.7
MEDIUMCVE-2025-29817
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.... Read more
Affected Products : power_automate_for_desktop- Published: Apr. 15, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
9.0
CRITICALCVE-2025-32911
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.... Read more
- Published: Apr. 15, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
5.9
MEDIUMCVE-2025-28198
A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-24949
In JotUrl 2.0, is possible to bypass security requirements during the password change process.... Read more
Affected Products : joturl- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-24948
In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.... Read more
Affected Products : joturl- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2024-36842
An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication