Latest CVE Feed
-
7.5
HIGHCVE-2025-59527
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the /api/v1/fetch-links endpoint of the Flowise application. This vulnerability... Read more
Affected Products : flowise- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
10.0
CRITICALCVE-2025-59528
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP se... Read more
Affected Products : flowise- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-56264
The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.... Read more
Affected Products : oneblog- Published: Sep. 16, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-57631
SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module... Read more
Affected Products : tduck- Published: Sep. 16, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2025-5717
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploy... Read more
Affected Products :- Published: Sep. 23, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-57407
A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browse... Read more
Affected Products :- Published: Sep. 23, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-58123
Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.... Read more
Affected Products : bgp_monitoring- Published: Aug. 28, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-58124
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.... Read more
Affected Products : check_mk_python_api- Published: Aug. 28, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cryptography
-
6.9
MEDIUMCVE-2025-58125
Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.... Read more
Affected Products : freebox_v6_agent- Published: Aug. 28, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-58126
Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.... Read more
Affected Products : vmware_vsan- Published: Aug. 28, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2025-55904
Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is sent to the SBI of either AMF, AUSF, BSF, NRF, NSSF, PCF, SMF, UDM,... Read more
Affected Products : open5gs- Published: Sep. 17, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-57055
WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using... Read more
Affected Products : wondercms- Published: Sep. 17, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-35432
CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.... Read more
Affected Products : thorium- Published: Sep. 17, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-35434
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.... Read more
Affected Products : thorium- Published: Sep. 17, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-35433
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.... Read more
Affected Products : thorium- Published: Sep. 17, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-58127
Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.... Read more
Affected Products : dell_powerscale- Published: Aug. 28, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-59328
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payload that, when processed, consumes ... Read more
Affected Products : fory- Published: Sep. 15, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-4760
An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted A... Read more
Affected Products :- Published: Sep. 23, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-26514
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modif... Read more
Affected Products : storagegrid- Published: Sep. 19, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-26515
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an unauthenticated attacker to ch... Read more
Affected Products : storagegrid- Published: Sep. 19, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Server-Side Request Forgery