Latest CVE Feed
-
9.8
CRITICALCVE-2025-26210
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-56189
In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction... Read more
Affected Products : android- Published: Sep. 04, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-53694
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): ... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2025-56608
The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cry... Read more
Affected Products : android_corona_virus_tracker_app_for_india- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-57052
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing al... Read more
Affected Products : cjson- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-57146
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.... Read more
Affected Products : complaint_management_system- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-57147
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.... Read more
Affected Products : complaint_management_system- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-55175
QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was no... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-52586
The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker with access to a local network to intercept, manipulate, replay, or for... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2025-54544
QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By d... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-58458
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attac... Read more
Affected Products : git_client- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2025-54172
QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin user is... Read more
Affected Products : quick.cms- Published: Aug. 20, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-54174
QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content defined... Read more
Affected Products : quick.cms- Published: Aug. 20, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-54175
QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality. An attacker can craft a malicious URL that results in arbitrary JavaScript execution in the victim's browser when opened. The vendor was notified early... Read more
Affected Products : quick.cms.ext- Published: Aug. 20, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-54540
QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notifi... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-58459
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-54541
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early ... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.9
MEDIUMCVE-2025-54542
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't resp... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-54543
QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By def... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2009-3369
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNa... Read more
- Published: Sep. 24, 2009
- Modified: Sep. 08, 2025