Latest CVE Feed
-
6.4
MEDIUMCVE-2025-9851
The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products : appointmind- Published: Sep. 17, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-25153
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to ... Read more
- Published: Mar. 13, 2024
- Modified: Sep. 19, 2025
-
8.1
HIGHCVE-2024-0088
NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering... Read more
- Published: May. 14, 2024
- Modified: Sep. 19, 2025
-
9.1
CRITICALCVE-2025-10643
Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Wondershare Repairit. Authentication is not required to exploit this... Read more
Affected Products : repairit- Published: Sep. 17, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-10644
Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on Wondershare Repairit. Authentication is not required to exploit this vulnerability. ... Read more
Affected Products : repairit- Published: Sep. 17, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2024-0100
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.... Read more
- Published: May. 14, 2024
- Modified: Sep. 19, 2025
-
9.8
CRITICALCVE-2024-32022
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.... Read more
Affected Products : kohya_ss- Published: Apr. 16, 2024
- Modified: Sep. 19, 2025
-
5.9
MEDIUMCVE-2024-3689
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads t... Read more
Affected Products : o2oa- Published: Apr. 12, 2024
- Modified: Sep. 19, 2025
-
10.0
CRITICALCVE-2025-8276
Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Improper Control of Generation... Read more
Affected Products :- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-8904
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Use... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-2404
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 before 20250916.... Read more
Affected Products :- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-6943
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) ver... Read more
Affected Products : gx_works3 mc_works64 gx_works2 melsoft_navigator mt_works2 ezsocket fr_configurator2 mx_component got1000 got2000- Published: Jan. 30, 2024
- Modified: Sep. 19, 2025
-
7.5
HIGHCVE-2023-6942
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 vers... Read more
Affected Products : gx_works3 mc_works64 gx_works2 melsoft_navigator mt_works2 ezsocket fr_configurator2 mx_component got1000 got2000- Published: Jan. 30, 2024
- Modified: Sep. 19, 2025
-
7.1
HIGHCVE-2025-5023
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the pr... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-5022
Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the produ... Read more
Affected Products :- Published: Jul. 10, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authentication
-
10.0
CRITICAL- Published: Sep. 04, 2025
- Modified: Sep. 18, 2025
-
6.8
MEDIUMCVE-2024-47120
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges.... Read more
- Published: Sep. 10, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-52074
PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.... Read more
Affected Products : online_shopping_portal- Published: Sep. 12, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-10372
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site scripting. It is possible to initiate the ... Read more
Affected Products : i-educar- Published: Sep. 13, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-10373
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educar_turma_tipo_cad.php. Such manipulation of the argument nm_tipo leads to cross site scripting. It is possi... Read more
Affected Products : i-educar- Published: Sep. 13, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting