Latest CVE Feed
-
6.5
MEDIUMCVE-2025-58065
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and accessible, despite ... Read more
- Published: Sep. 11, 2025
- Modified: Sep. 24, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-59055
InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability in InstantCMS up to and including 2.17.3 allows authenticated remote attackers to make nay HTTP/HTTPS request via the package paramete... Read more
Affected Products : instantcms- Published: Sep. 11, 2025
- Modified: Sep. 24, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-55319
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : visual_studio_code- Published: Sep. 12, 2025
- Modified: Sep. 24, 2025
-
4.0
MEDIUMCVE-2025-36082
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 24, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-8531
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5 digits of seria... Read more
Affected Products :- Published: Sep. 19, 2025
- Modified: Sep. 24, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-9566
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful atta... Read more
- Published: Sep. 05, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-36354
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potential... Read more
Affected Products :- Published: Sep. 06, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-36342
Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.... Read more
Affected Products :- Published: Sep. 06, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-21947
Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level.... Read more
Affected Products :- Published: Sep. 06, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-9570
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-57605
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation a... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-57602
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot ... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-57601
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the controller sends... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-57433
The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpoint (/cwi/ajax_request/get_data.php), an authenticated attacker (even with a low-privileged account like g... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-57432
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-57430
Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-52367
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.... Read more
Affected Products :- Published: Sep. 22, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-30200
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.... Read more
Affected Products : deebot_x1s_pro_firmware deebot_x1s_pro deebot_x1_pro_omni_firmware deebot_x1_pro_omni deebot_x1_omni_firmware deebot_x1_omni deebot_x1_turbo_firmware deebot_x1_turbo deebot_t10_firmware deebot_t10 +16 more products- Published: Sep. 05, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Cryptography
-
7.5
HIGHCVE-2025-30199
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.... Read more
Affected Products : deebot_x1s_pro_firmware deebot_x1s_pro deebot_x1_pro_omni_firmware deebot_x1_pro_omni deebot_x1_omni_firmware deebot_x1_omni deebot_x1_turbo_firmware deebot_x1_turbo deebot_t10_firmware deebot_t10 +16 more products- Published: Sep. 05, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration
-
6.3
MEDIUMCVE-2025-30198
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.... Read more
Affected Products : deebot_x1s_pro_firmware deebot_x1s_pro deebot_x1_pro_omni_firmware deebot_x1_pro_omni deebot_x1_omni_firmware deebot_x1_omni deebot_x1_turbo_firmware deebot_x1_turbo deebot_t10_firmware deebot_t10 +16 more products- Published: Sep. 05, 2025
- Modified: Sep. 23, 2025
- Vuln Type: Misconfiguration