| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21474 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing commands from A2dp sink command queue. | ||
| CVE-2025-21473 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption when using Virtual cdm (Camera Data Mover) to write registers. | ||
| CVE-2025-21461 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption when programming registers through virtual CDM. | ||
| CVE-2025-21458 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously. | ||
| CVE-2025-21456 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently. | ||
| CVE-2025-21455 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while submitting blob data to kernel space though IOCTL. | ||
| CVE-2025-21452 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. | ||
| CVE-2025-8420 | Hig | 0.46 | 8.1 | 0.01 | Aug 6, 2025 | Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a… | ||
| CVE-2025-54634 | Hig | 0.52 | 8.0 | 0.00 | Aug 6, 2025 | Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54627 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2025 | Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-8654 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2025 | Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this… | ||
| CVE-2025-8653 | Hig | 0.57 | 8.8 | 0.00 | Aug 6, 2025 | Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR. Authentication is not required to exploit this… | ||
| CVE-2025-7036 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2025 | The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | ||
| CVE-2025-54622 | Hig | 0.54 | 8.3 | 0.00 | Aug 6, 2025 | Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54611 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2025 | EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54607 | Hig | 0.50 | 7.7 | 0.00 | Aug 6, 2025 | Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54606 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2025 | Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-54655 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2025 | Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module. | ||
| CVE-2025-54653 | Hig | 0.55 | 8.4 | 0.00 | Aug 6, 2025 | Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module. | ||
| CVE-2025-54652 | Hig | 0.55 | 8.4 | 0.00 | Aug 6, 2025 | Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module. | ||
| CVE-2025-54884 | Hig | 0.50 | — | 0.00 | Aug 6, 2025 | Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to… | ||
| CVE-2025-54872 | Hig | 0.50 | — | 0.00 | Aug 6, 2025 | onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image,… | ||
| CVE-2025-54801 | Hig | 0.42 | 7.5 | 0.00 | Aug 6, 2025 | Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds… | ||
| CVE-2025-53534 | Hig | 0.43 | — | 0.01 | Aug 5, 2025 | RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take… | ||
| CVE-2013-10065 | Hig | 0.52 | 7.5 | 0.01 | Aug 5, 2025 | A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange… | ||
| CVE-2012-10034 | Hig | 0.52 | 7.5 | 0.01 | Aug 5, 2025 | ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The… | ||
| CVE-2012-10032 | Hig | 0.60 | — | 0.01 | Aug 5, 2025 | Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw… | ||
| CVE-2012-10031 | Hig | 0.59 | — | 0.01 | Aug 5, 2025 | BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a… | ||
| CVE-2012-10029 | Hig | 0.59 | — | 0.03 | Aug 5, 2025 | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. | ||
| CVE-2012-10028 | Hig | 0.59 | — | 0.01 | Aug 5, 2025 | Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the… | ||
| CVE-2012-10024 | Hig | 0.42 | — | 0.01 | Aug 5, 2025 | XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can… | ||
| CVE-2025-51628 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter. | ||
| CVE-2025-7674 | Hig | 0.46 | — | 0.00 | Aug 5, 2025 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality… | ||
| CVE-2025-54254 | Hig | 0.63 | 8.6 | 0.77 | Aug 5, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local… | ||
| CVE-2025-43978 | Hig | 0.48 | 7.4 | 0.01 | Aug 5, 2025 | Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute… | ||
| CVE-2025-43979 | Hig | 0.48 | 7.4 | 0.06 | Aug 5, 2025 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands with root privileges via crafted payloads to the xml_action.cgi?method= endpoint. | ||
| CVE-2025-29745 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2025 | A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file. | ||
| CVE-2025-7033 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute… | ||
| CVE-2025-7032 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute… | ||
| CVE-2025-7025 | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute… | ||
| CVE-2025-6207 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with… | ||
| CVE-2025-5061 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with… | ||
| CVE-2025-41698 | — | Hig | 0.51 | 7.8 | 0.00 | Aug 5, 2025 | A low privileged local attacker can interact with the affected service although user-interaction should not be allowed. | |
| CVE-2025-7050 | Hig | 0.47 | 7.2 | 0.00 | Aug 5, 2025 | The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes… | ||
| CVE-2025-54868 | Hig | 0.00 | 7.5 | 0.00 | Aug 5, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch… | ||
| CVE-2025-54870 | Hig | 0.50 | — | 0.00 | Aug 5, 2025 | VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18.… | ||
| CVE-2025-54865 | Hig | 0.47 | 7.3 | 0.00 | Aug 5, 2025 | Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed. | ||
| CVE-2025-54803 | Hig | 0.42 | 7.5 | 0.01 | Aug 5, 2025 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML… | ||
| CVE-2025-54780 | Hig | 0.43 | 7.7 | 0.00 | Aug 5, 2025 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2. | ||
| CVE-2025-54135 | Hig | 0.55 | 8.5 | 0.02 | Aug 5, 2025 | Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the… |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing commands from A2dp sink command queue.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when programming registers through virtual CDM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while submitting blob data to kernel space though IOCTL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- risk 0.46cvss 8.1epss 0.01
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a…
- risk 0.52cvss 8.0epss 0.00
Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.57cvss 8.8epss 0.00
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.57cvss 8.8epss 0.01
Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this…
- risk 0.57cvss 8.8epss 0.00
Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Kenwood DMX958XR. Authentication is not required to exploit this…
- risk 0.42cvss 7.5epss 0.01
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
- risk 0.54cvss 8.3epss 0.00
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.47cvss 7.3epss 0.00
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.50cvss 7.7epss 0.00
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.47cvss 7.3epss 0.00
Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.53cvss 8.1epss 0.00
Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.
- risk 0.55cvss 8.4epss 0.00
Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.
- risk 0.55cvss 8.4epss 0.00
Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module.
- risk 0.50cvss —epss 0.00
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to…
- risk 0.50cvss —epss 0.00
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image,…
- risk 0.42cvss 7.5epss 0.00
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds…
- risk 0.43cvss —epss 0.01
RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obtains the backend login path of RatPanel (including but not limited to weak default paths, brute-force cracking, etc.), they can execute system commands or take…
- risk 0.52cvss 7.5epss 0.01
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange…
- risk 0.52cvss 7.5epss 0.01
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The…
- risk 0.60cvss —epss 0.01
Maxthon3 version 3.2.2 build 1000 and prior are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw…
- risk 0.59cvss —epss 0.01
BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a…
- risk 0.59cvss —epss 0.03
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
- risk 0.59cvss —epss 0.01
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the…
- risk 0.42cvss —epss 0.01
XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can…
- risk 0.49cvss 7.5epss 0.00
Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter.
- risk 0.46cvss —epss 0.00
Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality…
- risk 0.63cvss 8.6epss 0.77
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local…
- risk 0.48cvss 7.4epss 0.01
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute…
- risk 0.48cvss 7.4epss 0.06
An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands with root privileges via crafted payloads to the xml_action.cgi?method= endpoint.
- risk 0.49cvss 7.5epss 0.00
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.
- risk 0.51cvss 7.8epss 0.00
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…
- risk 0.51cvss 7.8epss 0.00
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…
- risk 0.51cvss 7.8epss 0.00
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…
- risk 0.49cvss 7.5epss 0.01
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with…
- risk 0.49cvss 7.5epss 0.01
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with…
- risk 0.51cvss 7.8epss 0.00
A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.
- risk 0.47cvss 7.2epss 0.00
The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in all versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes…
- risk 0.00cvss 7.5epss 0.00
LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch…
- risk 0.50cvss —epss 0.00
VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18.…
- risk 0.47cvss 7.3epss 0.00
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by the Tilesheets extension allows users to insert and potentially execute malicious SQL code. This issue has not been fixed.
- risk 0.42cvss 7.5epss 0.01
js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML…
- risk 0.43cvss 7.7epss 0.00
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.
- risk 0.55cvss 8.5epss 0.02
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the…