CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2025-39247

    Last Modified: 15 Apr 2026

    There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

    Published: 29 Aug 2025
    5.3
    Medium

    CVE-2025-39246

    Last Modified: 15 Apr 2026

    There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 29 Aug 2025
    4.7
    Medium

    CVE-2025-39245

    Last Modified: 15 Apr 2026

    There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

    Published: 29 Aug 2025
    6.3
    Medium

    CVE-2025-9604

    Last Modified: 15 Apr 2026

    A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument AuthSecretKey/StateSecretKey/OAuthTokenSecretKey leads to use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. To fix this issue, it is recommended to deploy a patch. The vendor replied to the GitHub issue (translated from simplified Chinese): "For scenarios requiring encryption, we will implement user-defined key management through configuration and optimize the use of encryption tools, such as random salt."

    Published: 29 Aug 2025
    2.1
    Low

    CVE-2025-9603

    Last Modified: 11 Sept 2025

    A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname can lead to command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Aug 2025
    2.1
    Low

    CVE-2025-9602

    Last Modified: 11 Sept 2025

    A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9601

    Last Modified: 2 Sept 2025

    A vulnerability was detected in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /setting/employee_salary_setup.php. The manipulation of the argument ddlEmpName results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9600

    Last Modified: 2 Sept 2025

    A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /setting/member_type_setup.php. The manipulation of the argument txtMemberType leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9599

    Last Modified: 2 Sept 2025

    A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /setting/month_setup.php. Executing manipulation of the argument txtMonthName can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2024-54554

    Last Modified: 2 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

    Published: 29 Aug 2025
    7.8
    High

    CVE-2025-43187

    Last Modified: 28 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Running an hdiutil command may unexpectedly execute arbitrary code.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-43284

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

    Published: 29 Aug 2025
    4.3
    Medium

    CVE-2024-54568

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an unexpected app termination.

    Published: 29 Aug 2025
    3.3
    Low

    CVE-2024-44271

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without an indicator.

    Published: 29 Aug 2025
    7.8
    High

    CVE-2025-43268

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.

    Published: 29 Aug 2025
    3.3
    Low

    CVE-2025-43255

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

    Published: 29 Aug 2025
    7.3
    High

    CVE-2025-40927

    Last Modified: 15 Apr 2026

    CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows HTTP response header injection, which can be used for reflected XSS or open redirect under certain conditions. Although some validation exists, it can be bypassed using URL-encoded values, allowing an attacker to inject untrusted content into the response via query parameters. As a result, an attacker can inject a line break (e.g. %0A) into the parameter value, causing the server to split the HTTP response and inject arbitrary headers or even an HTML/JavaScript body, leading to reflected cross-site scripting (XSS), open redirect or other attacks. The issue documented in CVE-2010-4410 https://www.cve.org/CVERecord?id=CVE-2010-4410 is related but the fix was incomplete. Impact By injecting %0A (newline) into a query string parameter, an attacker can: * Break the current HTTP header * Inject a new header or entire body * Deliver a script payload that is reflected in the server’s response That can lead to the following attacks: * reflected XSS * open redirect * cache poisoning * header manipulation

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9598

    Last Modified: 2 Sept 2025

    A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/year_setup.php. Performing manipulation of the argument txtXYear results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9597

    Last Modified: 2 Sept 2025

    A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the file /o_dashboard/rented_all_info.php. Such manipulation of the argument uid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 29 Aug 2025
    8.4
    High

    CVE-2025-56577

    Last Modified: 8 Sept 2025

    An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.

    Published: 29 Aug 2025
    8.1
    High

    CVE-2024-46916

    Last Modified: 9 Sept 2025

    Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions, enable recovery of TPM Disk Encryption keys and decryption of the Windows system partition.

    Published: 29 Aug 2025
    5.4
    Medium

    CVE-2025-55579

    Last Modified: 9 Sept 2025

    SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

    Published: 29 Aug 2025
    7.8
    High

    CVE-2023-41471

    Last Modified: 3 Nov 2025

    Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript.

    Published: 29 Aug 2025
    9.8
    Critical

    CVE-2024-46484

    Last Modified: 8 Sept 2025

    TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

    Published: 29 Aug 2025
    8.1
    High

    CVE-2024-46917

    Last Modified: 9 Sept 2025

    Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile changes.

    Published: 29 Aug 2025
    9.8
    Critical

    CVE-2025-44033

    Last Modified: 19 Nov 2025

    SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java

    Published: 29 Aug 2025
    4
    Medium

    CVE-2025-54142

    Last Modified: 15 Apr 2026

    Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.

    Published: 29 Aug 2025
    5.4
    Medium

    CVE-2025-55580

    Last Modified: 9 Sept 2025

    SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.

    Published: 29 Aug 2025
    7.5
    High

    CVE-2025-55763

    Last Modified: 9 Sept 2025

    Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

    Published: 29 Aug 2025
    5.5
    Medium

    CVE-2025-9596

    Last Modified: 3 Sept 2025

    A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /login.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9595

    Last Modified: 3 Sept 2025

    A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and could be used.

    Published: 28 Aug 2025
    3.4
    Low

    CVE-2025-48979

    Last Modified: 15 Apr 2026

    An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.

    Published: 28 Aug 2025
    5.5
    Medium

    CVE-2025-9594

    Last Modified: 3 Sept 2025

    A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation of the argument vid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Aug 2025
    5.5
    Medium

    CVE-2025-9593

    Last Modified: 3 Sept 2025

    A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unit_status_info.php. Executing manipulation of the argument usid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

    Published: 28 Aug 2025
    7.3
    High

    CVE-2025-58062

    Last Modified: 15 Apr 2026

    LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows platform connect to an attacker controlled MCP server, attackers could provision a malicious authorization server endpoint to silently achieve an OS command injection attack in the open() invocation, leading to client system compromise. This issue has been patched in version 0.1.12.

    Published: 28 Aug 2025
    5.5
    Medium

    CVE-2025-58061

    Last Modified: 15 Apr 2026

    OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world readable and that would allow non-privileged users to access sensitive data such as databases of k8s workload. The rawfile-localpv storage class creates persistent volume data under /var/csi/rawfile/ on Kubernetes hosts by default. However, the directory and data in it are world-readable. It allows non-privileged users to access the whole persistent volume data, and those can include sensitive information such as a whole database if the Kubernetes tenants are running MySQL or PostgreSQL in a container so it could lead to a database breach. This issue has been patched in version 0.10.0.

    Published: 28 Aug 2025
    5.5
    Medium

    CVE-2025-9592

    Last Modified: 3 Sept 2025

    A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/bill_info.php. Performing manipulation of the argument vid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 28 Aug 2025
    1.9
    Low

    CVE-2025-9591

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in ZrLog up to 3.1.5. This vulnerability affects unknown code of the file /api/admin/template/config of the component Theme Configuration Form. Such manipulation of the argument footerLink leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-58058

    Last Modified: 15 Apr 2026

    xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

    Published: 28 Aug 2025
    2
    Low

    CVE-2025-9590

    Last Modified: 15 Apr 2026

    A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerability is an unknown functionality. The manipulation of the argument gohome leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    1.1
    Low

    CVE-2025-9589

    Last Modified: 15 Apr 2026

    A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/shadow. Executing manipulation can lead to use of default password. The attack needs to be launched locally. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9586

    Last Modified: 2 Oct 2025

    A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be performed from a remote location. The exploit is publicly available and might be used.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9585

    Last Modified: 2 Oct 2025

    A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9584

    Last Modified: 2 Oct 2025

    A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9583

    Last Modified: 2 Oct 2025

    A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

    Published: 28 Aug 2025
    7.5
    High

    CVE-2025-6203

    Last Modified: 18 Dec 2025

    A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9582

    Last Modified: 11 Sept 2025

    A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9581

    Last Modified: 11 Sept 2025

    A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9580

    Last Modified: 12 Sept 2025

    A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9579

    Last Modified: 11 Sept 2025

    A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP Handler. This manipulation of the argument enable causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025