Latest CVE Feed
- 
                                
                                
7.5
HIGHCVE-2025-60751
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.... Read more
Affected Products :- Published: Oct. 21, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-46556
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validati... Read more
Affected Products : mantisbt- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-35021
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
7.8
HIGHCVE-2025-10934
GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha... Read more
Affected Products : gimp- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-12207
A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed locally. The explo... Read more
Affected Products : kamailio- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.5
MEDIUMCVE-2025-12206
A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been published and may b... Read more
Affected Products : kamailio- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-12205
A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core/cfg.lex of the component Configuration File Handler. The manipulation results in use after free. The attack must be initiated from a l... Read more
Affected Products : kamailio- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-12204
A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rvalue.c of the component Configuration File Handler. The manipulation leads to heap-based buffer overflow. The attack must be carried ou... Read more
Affected Products : kamailio- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.4
MEDIUMCVE-2025-36172
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site... Read more
Affected Products : cloud_pak_for_business_automation- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.0
HIGHCVE-2025-34501
Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often throu... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
6.8
MEDIUMCVE-2025-11193
A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
6.0
MEDIUMCVE-2024-13998
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password has... Read more
Affected Products : xi- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.4
CRITICALCVE-2024-13997
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, a... Read more
Affected Products : xi- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.1
MEDIUMCVE-2021-47698
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrar... Read more
Affected Products : xi- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.1
MEDIUMCVE-2016-15054
Nagios XI versions prior to 5.4.0 are vulnerable to cross-site scripting (XSS) via the jQuery Migrate library. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a vict... Read more
Affected Products : xi- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-63563
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimat... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-63293
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization check... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
6.8
MEDIUMCVE-2025-60892
An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys fil... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-52179
Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahrw/jsp/gsfr_feditorHTML.jsp endpoint.... Read more
Affected Products :- Published: Oct. 30, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.5
HIGHCVE-2025-50735
Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Path Traversal