Latest CVE Feed
-
9.9
CRITICALCVE-2025-30220
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XM... Read more
- Published: Jun. 10, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
6.5
MEDIUMCVE-2022-40733
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-c... Read more
- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
9.8
CRITICALCVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission ... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
8.5
HIGHCVE-2025-5689
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.... Read more
Affected Products : authd- Published: Jun. 16, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
8.0
HIGHCVE-2025-46815
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the client receives an ... Read more
Affected Products : zitadel- Published: May. 06, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-42004
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
5.5
MEDIUMCVE-2025-32915
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.... Read more
- Published: May. 22, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-41145
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious appl... Read more
Affected Products : teams- Published: Dec. 18, 2024
- Modified: Aug. 26, 2025
-
5.3
MEDIUMCVE-2025-8210
A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component com.yeelight.cherry. The manipulation leads to improper expor... Read more
- Published: Jul. 26, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
5.8
MEDIUMCVE-2025-9424
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch_import.php?a=branch_list. Such manipulation of the argument province leads to os command injection. The a... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-9422
A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit... Read more
Affected Products :- Published: Aug. 25, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-9137
A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to cross site scripting. The attack can be executed remotely. The exploit has been discl... Read more
Affected Products : scada-lts- Published: Aug. 19, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-54336
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in adm... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-50674
An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.... Read more
Affected Products :- Published: Aug. 22, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2024-45271
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.... Read more
- Published: Oct. 15, 2024
- Modified: Aug. 26, 2025
-
9.8
CRITICALCVE-2023-2530
A privilege escalation allowing remote code execution was discovered in the orchestration service.... Read more
Affected Products : puppet_enterprise- EPSS Score: %3.12
- Published: Jun. 07, 2023
- Modified: Aug. 26, 2025
-
6.8
MEDIUMCVE-2018-10631
The 8840 Clinician Programmer executes the application program from the 8870 Application Card. An attacker with physical access to an 8870 Application Card and sufficient technical capability can modify the contents of this card, including the binary exec... Read more
- EPSS Score: %0.15
- Published: Jul. 13, 2018
- Modified: Aug. 26, 2025
-
7.5
HIGHCVE-2024-37302
Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media. The default rate limit strategy is ... Read more
Affected Products : synapse- Published: Dec. 03, 2024
- Modified: Aug. 26, 2025
-
5.3
MEDIUMCVE-2024-37303
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then al... Read more
Affected Products : synapse- Published: Dec. 03, 2024
- Modified: Aug. 26, 2025
-
8.2
HIGHCVE-2024-52805
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify de... Read more
Affected Products : synapse- Published: Dec. 03, 2024
- Modified: Aug. 26, 2025