Latest CVE Feed
-
5.0
MEDIUMCVE-2025-24021
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the i... Read more
Affected Products : itop- Published: May. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-9306
A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/notice/addNotice. The manipulation of the argument noticeSubject results in cross site scripting. It i... Read more
Affected Products : advanced_school_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-9307
A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has bee... Read more
Affected Products : online_course_registration- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-57761
WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_remover.php endpoint, specifically in the id_funcionario parameter. This vulnerability allows attackers to exec... Read more
Affected Products : wegia- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-57762
WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Stored Cross-Site Scripting (XSS) vulnerability in the dependente_docdependente.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious s... Read more
Affected Products : wegia- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-57763
WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the insere_despacho.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts... Read more
Affected Products : wegia- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-9311
A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fair/addfair.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the atta... Read more
Affected Products : apartment_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-25717
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.... Read more
Affected Products : ruckus_wireless_admin smartzone_ap smartzone r310 r500 r600 t300 t301n t301s h320 +52 more products- Actively Exploited
- EPSS Score: %94.23
- Published: Feb. 13, 2023
- Modified: Aug. 22, 2025
-
6.1
MEDIUMCVE-2023-49225
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As fo... Read more
Affected Products : r310_firmware zonedirector_firmware h320_firmware h510_firmware r710_firmware r720_firmware t610_firmware t710_firmware r510_firmware r750_firmware +65 more products- EPSS Score: %0.32
- Published: Dec. 07, 2023
- Modified: Aug. 22, 2025
-
6.8
MEDIUMCVE-2024-45062
A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which can lead to a arbitrary code execution in a privileged service. To trigger th... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-55734
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when ... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-55735
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe ... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-55736
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.... Read more
Affected Products : flaskblog- Published: Aug. 19, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-55731
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injection. This vulnerability is fixed in 15.74.2 and 14.96.15.... Read more
Affected Products : frappe- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-55732
Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injection through specially crafted requests, allowing malicious people to access sensitive information. This vulnerability is a bypass of the... Read more
Affected Products : frappe- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-32451
A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and... Read more
Affected Products : pdf_reader- Published: Aug. 13, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-47152
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially le... Read more
Affected Products : pdf-xchange_editor- Published: Aug. 05, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-27931
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the... Read more
Affected Products : pdf-xchange_editor- Published: Aug. 05, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2024-51447
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This c... Read more
Affected Products : polarion_alm- Published: May. 13, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-40566
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauth... Read more
Affected Products : simatic_pcs_neo- Published: May. 13, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication