Latest CVE Feed
-
9.1
CRITICALCVE-2025-9287
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.... Read more
Affected Products : cipher-base- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-5086
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.... Read more
Affected Products : delmia_apriso- Actively Exploited
- Published: Jun. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-9288
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.... Read more
Affected Products : sha.js- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-9262
A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The att... Read more
Affected Products : mcp-cli- Published: Aug. 20, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9296
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the ... Read more
Affected Products : emlog- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-9300
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be ... Read more
Affected Products : libsixel- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-9308
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this att... Read more
Affected Products : yarn- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-9310
A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vulnerability is an unknown functionality of the file /carRental_war/druid/login.html of the component Druid. Executing manipulation can le... Read more
Affected Products : carrental- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
6.3
MEDIUMCVE-2025-8916
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS ... Read more
Affected Products : bouncy_castle_for_java- Published: Aug. 13, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-8885
Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BC-FJA bc-fips on All allows Excessive Allocation. This vulnerability is associate... Read more
Affected Products : bouncy_castle_for_java- Published: Aug. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-49831
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there... Read more
Affected Products : conjur- Published: Jul. 15, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-6436
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: through 20231215.... Read more
Affected Products : web_sablonu_yazilimi- Published: Jan. 02, 2024
- Modified: Sep. 12, 2025
-
6.1
MEDIUMCVE-2025-2488
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox allows Cross-Site Scripting (XSS).This issue affects SambaBox: before 5.1.... Read more
Affected Products : sambabox- Published: May. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2421
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.... Read more
Affected Products : sambabox- Published: May. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-1301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS.This issue affects Library Automation System: before 21.6.... Read more
Affected Products : library_automation_system- Published: May. 02, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2024-12604
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.This issue aff... Read more
Affected Products : tap\&sign- Published: Mar. 10, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-8262
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.... Read more
Affected Products : student_affairs_information_system- Published: Mar. 03, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-8261
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927.... Read more
Affected Products : student_affairs_information_system- Published: Mar. 03, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-7016
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek Informatics Smart Doctor's allows Stored XSS required admin privileges.This issue affects Smart Doctor: through 21.11.2024. NOTE: The v... Read more
Affected Products : smart_doctor- Published: Nov. 21, 2024
- Modified: Sep. 12, 2025
-
9.8
CRITICALCVE-2024-5960
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.... Read more
Affected Products : panel- Published: Sep. 18, 2024
- Modified: Sep. 12, 2025