Latest CVE Feed
-
7.8
HIGHCVE-2025-53919
An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, with weak permissions, during installation and uninstallation. A low-privileged attacker with local access could po... Read more
Affected Products : dell_color_management- Published: Dec. 17, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2025-53922
Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may bypass intended restrictions on Contributions and Transactions. Version 1.2... Read more
Affected Products : galette- Published: Dec. 19, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-50526
Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.... Read more
- Published: Dec. 23, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-50681
igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a crafted IGMPv3 membership report packet with a malicious source address. Due to insufficient validation in the `recv_igmp()` function in src... Read more
Affected Products : igmpproxy- Published: Dec. 19, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-51962
A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.... Read more
Affected Products : microstudio- Published: Dec. 15, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-52196
Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary HTTP requests via a crafted HTML file containing an iframe.... Read more
Affected Products : ctera- Published: Dec. 16, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-52493
PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simp... Read more
Affected Products : runbook_automation- Published: Dec. 10, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-52582
An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerabil... Read more
Affected Products : grassroots_dicom- Published: Dec. 16, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-68927
Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user inpu... Read more
Affected Products : libredesk- Published: Dec. 27, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-25814
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.... Read more
Affected Products : mynet- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-25812
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.... Read more
Affected Products : mynet- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2024-27708
Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.... Read more
Affected Products : mynet- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-0565
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing manipulation of the argument del can lead to sql injection. The attack can be executed remot... Read more
Affected Products :- Published: Jan. 02, 2026
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-27480
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.... Read more
Affected Products : vvvebjs- Published: Dec. 29, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-25183
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.... Read more
Affected Products : vvvebjs- Published: Dec. 29, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-25182
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.... Read more
Affected Products : vvvebjs- Published: Dec. 29, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-15353
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is the function edit_admin_query of the file /admin/edit_admin_query.php. Performing manipulation of the argument Username results in sql injection. It is possible to ini... Read more
Affected Products : society_management_system- Published: Dec. 30, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-15243
A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has... Read more
Affected Products : simple_stock_system- Published: Dec. 30, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-15209
A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the file /home/editfood.php. This manipulation of the argument a/b/c/d causes sql injection. The attack may be initiated remotely. The expl... Read more
Affected Products : refugee_food_management_system- Published: Dec. 29, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
7.1
HIGHCVE-2023-53775
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the user... Read more
- Published: Dec. 10, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authentication