Latest CVE Feed
-
5.5
MEDIUMCVE-2025-8707
A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file AndroidManifest.xml of the component com.huuge.game.zjbox. The manipulation leads to improper export of android ap... Read more
Affected Products : huuge_box- Published: Aug. 08, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-8729
A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_files of the file backend/service/upload_service.py. The manipulation of the argument task_id leads to path tr... Read more
Affected Products : lmeterx- Published: Aug. 08, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-57118
An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-57117
A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-56706
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.... Read more
Affected Products :- Published: Sep. 16, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-56274
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users.... Read more
Affected Products :- Published: Sep. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-43375
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.... Read more
Affected Products : xcode- Published: Sep. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-8835
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer der... Read more
Affected Products : jasper- Published: Aug. 11, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8660
Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.... Read more
Affected Products : symantec_pgp_encryption- Published: Aug. 11, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-57520
A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary J... Read more
Affected Products : decap_cms- Published: Sep. 10, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-23045
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vuln... Read more
Affected Products : computer_vision_annotation_tool- Published: Jan. 28, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-52875
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Loc... Read more
Affected Products : kerio_control- Published: Jan. 31, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2024-35177
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to ... Read more
Affected Products : wazuh- Published: Feb. 03, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-10332
A vulnerability was found in cdevroe unmark up to 1.9.3. Impacted is an unknown function of the file application/views/marks/info.php. Performing manipulation of the argument Title results in cross site scripting. The attack is possible to be carried out ... Read more
- Published: Sep. 13, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-10331
A vulnerability has been found in cdevroe unmark up to 1.9.3. This issue affects some unknown processing of the file /application/controllers/Marks.php. Such manipulation of the argument Title leads to cross site scripting. The attack can be executed remo... Read more
- Published: Sep. 13, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-10330
A flaw has been found in cdevroe unmark up to 1.9.3. This vulnerability affects unknown code of the file application/views/layouts/topbar/searchform.php. This manipulation of the argument q causes cross site scripting. Remote exploitation of the attack is... Read more
- Published: Sep. 12, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10329
A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipulation of the argument url results in server-side request forgery. The attack may be launched remotely. The ... Read more
- Published: Sep. 12, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-41349
unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.... Read more
- Published: Aug. 29, 2024
- Modified: Sep. 16, 2025
-
7.5
HIGHCVE-2024-8361
In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device will restart aft... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Denial of Service
-
5.8
MEDIUMCVE-2024-7322
A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Denial of Service