Latest CVE Feed
-
5.4
MEDIUMCVE-2024-13309
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.... Read more
Affected Products : login_disable- Published: Jan. 09, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-0461
A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAja... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-0462
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&min... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0463
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action=UsersAjax&minip... Read more
Affected Products : lingdang_crm- Published: Jan. 14, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-8123
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the a... Read more
Affected Products : deer-wms-2- Published: Jul. 24, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-8124
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] l... Read more
Affected Products : deer-wms-2- Published: Jul. 25, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-8126
A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the ... Read more
Affected Products : deer-wms-2- Published: Jul. 25, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2023-4957
A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending... Read more
- Published: Oct. 11, 2023
- Modified: Aug. 28, 2025
-
10.0
CRITICALCVE-2025-34158
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres.... Read more
Affected Products : media_server- Published: Aug. 21, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-8125
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql... Read more
Affected Products : deer-wms-2- Published: Jul. 25, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2023-41234
NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
8.8
HIGHCVE-2023-42773
Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
8.8
HIGHCVE-2023-45217
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.8
HIGHCVE-2023-45221
Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : media_sdk- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
5.5
MEDIUMCVE-2023-45315
Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.8
HIGHCVE-2023-45320
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : vtune_profiler- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.8
HIGHCVE-2023-45736
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
5.5
MEDIUMCVE-2023-45846
Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
8.8
HIGHCVE-2023-46689
Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025
-
7.9
HIGHCVE-2023-46691
Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
- Published: May. 16, 2024
- Modified: Aug. 28, 2025