Latest CVE Feed
-
7.5
HIGHCVE-2025-54591
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to lack of access checking in the FreshRSS_Auth::hasAccess() function used by some of the tag/feed related endp... Read more
Affected Products : freshrss- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
9.5
CRITICALCVE-2025-34235
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS ... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Misconfiguration
-
7.3
HIGHCVE-2025-11178
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-10688
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument inv_no/insta_amt causes sql injection. The attack can b... Read more
Affected Products : pet_grooming_management_software- Published: Sep. 18, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-59689
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG ... Read more
Affected Products : email_security_gateway- Actively Exploited
- Published: Sep. 19, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.... Read more
Affected Products : goanywhere_managed_file_transfer- Actively Exploited
- Published: Sep. 18, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-8532
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing.This issue affects eBA Document and Workflow Management Syst... Read more
Affected Products :- Published: Sep. 19, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-8463
Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing.This issue affects SecHard: before 3.6.2-20250805.... Read more
Affected Products :- Published: Sep. 17, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2025-8276
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Patik... Read more
Affected Products :- Published: Sep. 16, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2025-59948
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attributes in feed content, so by finding a page that renders feed entries without CSP, it is possible to execute an XSS payload. The Allow A... Read more
Affected Products : freshrss- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-54592
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during logout. After a user logs out, the session cookie remains active and unchanged. The unchanged cookie could be reused by an attacker if... Read more
Affected Products : freshrss- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
9.2
CRITICALCVE-2025-34234
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (printerlogic/pi, prin... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cryptography
-
6.9
MEDIUMCVE-2025-34232
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind server-side request forgery (SSRF) vulnerability reachable via the /var/www/app/console_... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Server-Side Request Forgery
-
8.8
HIGHCVE-2025-34231
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a blind and non-blind server-side request forgery (SSRF) vulnerability. The '/var/www/app/consol... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Server-Side Request Forgery
-
8.8
HIGHCVE-2025-34225
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain a server-side request forgery (SSRF) vulnerability. The `console_release` directory is reachable... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Server-Side Request Forgery
-
10.0
CRITICALCVE-2025-34223
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) contain a default admin account and an installation‑time endpoint at `/admin/query/update_database.php`... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-34218
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployments) expose internal Docker containers through the gw Docker instance. The gateway publishes a /meta endpoi... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
10.0
CRITICALCVE-2025-34217
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh grou... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-34216
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version 20.0.2702 (VA deployments only) expose a set of unauthenticated REST API endpoints that return configuration files and clear‑text passw... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-34212
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads the VirtualBox Exte... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Supply Chain