Latest CVE Feed
-
7.2
HIGHCVE-2025-30067
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. ... Read more
Affected Products : kylin- Published: Mar. 27, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-2854
A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. The manipulation of the argument emp_type leads to sql injection. ... Read more
Affected Products : employees_payroll_management_system payroll_management_system payroll_management_system- Published: Mar. 27, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.5
CRITICALCVE-2025-2516
The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the upda... Read more
Affected Products : wps_office- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-29497
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-29496
libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29494
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29493
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29492
libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-29491
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29490
libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29489
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-29488
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-29487
An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29486
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-29485
libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-29484
An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-29483
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.... Read more
Affected Products : libming- Published: Mar. 27, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-22671
Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through 1.0.2.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-22670
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.7.2.... Read more
Affected Products : vikbooking_hotel_booking_engine_\&_pms- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22669
Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking allows Cross Site Request Forgery.This issue affects Awesome Event Booking: from n/a through 2.7.5.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery