Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-28402

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter... Read more

    Affected Products : ruoyi
    • Published: Apr. 07, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Authorization
  • 6.7

    MEDIUM
    CVE-2025-28401

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter... Read more

    Affected Products : ruoyi
    • Published: Apr. 07, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Authorization
  • 6.7

    MEDIUM
    CVE-2025-28400

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method... Read more

    Affected Products : ruoyi
    • Published: Apr. 07, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2025-3372

    A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The ex... Read more

    Affected Products : pcman_ftp_server ftp_server
    • Published: Apr. 07, 2025
    • Modified: May. 16, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-3371

    A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotel... Read more

    Affected Products : pcman_ftp_server ftp_server
    • Published: Apr. 07, 2025
    • Modified: May. 16, 2025
    • Vuln Type: Memory Corruption
  • 9.8

    CRITICAL
    CVE-2025-3248

    Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.... Read more

    Affected Products : langflow
    • Actively Exploited
    • Published: Apr. 07, 2025
    • Modified: May. 07, 2025
    • Vuln Type: Injection
  • 6.9

    MEDIUM
    CVE-2025-32014

    estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed... Read more

    Affected Products :
    • Published: Apr. 07, 2025
    • Modified: Apr. 08, 2025
    • Vuln Type: Misconfiguration
  • 4.8

    MEDIUM
    CVE-2025-31476

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as ... Read more

    Affected Products : tacjs tarteaucitronjs
    • Published: Apr. 07, 2025
    • Modified: Sep. 04, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.5

    MEDIUM
    CVE-2025-31475

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker wit... Read more

    Affected Products :
    • Published: Apr. 07, 2025
    • Modified: Apr. 08, 2025
    • Vuln Type: Misconfiguration
  • 5.5

    MEDIUM
    CVE-2025-31138

    tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker ... Read more

    Affected Products :
    • Published: Apr. 07, 2025
    • Modified: Apr. 08, 2025
    • Vuln Type: Misconfiguration
  • 6.5

    MEDIUM
    CVE-2025-30373

    Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing... Read more

    Affected Products : graylog
    • Published: Apr. 07, 2025
    • Modified: Apr. 08, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-3370

    A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible t... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 07, 2025
    • Modified: May. 07, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-3369

    A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /novel/friendLink/list. The manipulation of the argument sort leads to sql injection. The attack may be ... Read more

    Affected Products : novel-plus
    • Published: Apr. 07, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-30195

    An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.... Read more

    Affected Products : recursor
    • Published: Apr. 07, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Memory Corruption
  • 6.2

    MEDIUM
    CVE-2025-2251

    A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allow... Read more

    Affected Products : undertow
    • Published: Apr. 07, 2025
    • Modified: Jul. 14, 2025
    • Vuln Type: Authentication
  • 2.7

    LOW
    CVE-2025-27686

    Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with re... Read more

    Affected Products : unisphere_for_powermax
    • Published: Apr. 07, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Injection
  • 3.7

    LOW
    CVE-2025-3360

    A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.... Read more

    Affected Products : glib
    • Published: Apr. 07, 2025
    • Modified: Apr. 14, 2025
    • Vuln Type: Memory Corruption
  • 6.2

    MEDIUM
    CVE-2025-3359

    A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.... Read more

    Affected Products : gnuplot
    • Published: Apr. 07, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2025-3353

    A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument cost leads to sql injection. It is possible to ... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 07, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3352

    A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql inject... Read more

    Affected Products : old_age_home_management_system
    • Published: Apr. 07, 2025
    • Modified: May. 07, 2025
    • Vuln Type: Injection
Showing 20 of 293261 Results