Latest CVE Feed
-
5.5
MEDIUMCVE-2025-29213
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file.... Read more
Affected Products : jeewms- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-28399
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.... Read more
Affected Products : xmall- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Authorization
-
8.3
HIGHCVE-2025-27791
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. T... Read more
Affected Products : online- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-25456
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-24358
gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for ... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: May. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.6
MEDIUMCVE-2025-22903
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22900
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
2.1
LOWCVE-2024-42193
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability ... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2023-5616
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to ex... Read more
- Published: Apr. 15, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-3618
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on th... Read more
Affected Products : thinmanager- Published: Apr. 15, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Denial of Service
-
8.5
HIGHCVE-2025-3617
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. ... Read more
Affected Products : thinmanager- Published: Apr. 15, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-33028
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User intera... Read more
Affected Products : winzip- Published: Apr. 15, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-33027
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this... Read more
Affected Products : bandizip- Published: Apr. 15, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-33026
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerabili... Read more
Affected Products : peazip- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-29705
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.... Read more
Affected Products : code-gen- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28100
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.... Read more
Affected Products : dingfanzu- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2024-50960
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the unde... Read more
Affected Products : smp_111_firmware smp_111 smp_351_firmware smp_351 smp_352_firmware smp_352 smp_211_firmware smp_211 sme_211_firmware sme_211- Published: Apr. 15, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-42200
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2024-42189
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.... Read more
Affected Products : bigfix_platform- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2021-27289
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is im... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication