CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2025-9239

    Last Modified: 31 Oct 2025

    A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The manipulation of the argument STR_PARAM with the input Passw0rd leads to inadequate encryption strength. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult.

    Published: 20 Aug 2025
    5.5
    Medium

    CVE-2025-9238

    Last Modified: 15 Apr 2026

    A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affected is an unknown function of the file /student.php of the component Student Login. Executing manipulation of the argument email can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Aug 2025
    Unknown

    CVE-2010-20110

    Last Modified: 22 Apr 2026

    This CVE has the been REJECTED and will not be published by the CNA.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2025-55746

    Last Modified: 13 Jan 2026

    Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3.

    Published: 20 Aug 2025
    2
    Low

    CVE-2025-9237

    Last Modified: 25 Aug 2025

    A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

    Published: 20 Aug 2025
    2.1
    Low

    CVE-2025-9236

    Last Modified: 15 Sept 2026

    A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 2.12 mitigates this issue. Upgrading the affected component is advised. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced."

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-47054

    Last Modified: 22 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46849

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46852

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    2
    Low

    CVE-2025-9235

    Last Modified: 11 Sept 2025

    A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 20 Aug 2025
    2
    Low

    CVE-2025-9234

    Last Modified: 11 Sept 2025

    A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46856

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A low privileged attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46932

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46936

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    8.1
    High

    CVE-2025-8309

    Last Modified: 15 Apr 2026

    There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710, ServiceDesk Plus versions before 15110, ServiceDesk Plus MSP versions before 14940, and SupportCenter Plus versions before 14940.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46962

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    7
    High

    CVE-2025-6183

    Last Modified: 15 Apr 2026

    The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message.

    Published: 20 Aug 2025
    8.5
    High

    CVE-2025-6182

    Last Modified: 15 Apr 2026

    The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.

    Published: 20 Aug 2025
    5.4
    Medium

    CVE-2025-46998

    Last Modified: 25 Aug 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 20 Aug 2025
    8.5
    High

    CVE-2025-6181

    Last Modified: 15 Apr 2026

    The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

    Published: 20 Aug 2025
    8.5
    High

    CVE-2025-6180

    Last Modified: 15 Apr 2026

    The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.

    Published: 20 Aug 2025
    8.4
    High

    CVE-2010-20010

    Last Modified: 15 Apr 2026

    Foxit PDF Reader before 4.2.0.0928 does not properly bound-check the /Title entry in the PDF Info dictionary. A specially crafted PDF with an overlong Title string can overflow a fixed-size stack buffer, corrupt the Structured Exception Handler (SEH) chain, and lead to arbitrary code execution in the context of the user who opens the file.

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57830

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57831

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57832

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57825

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57826

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57827

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57828

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57829

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    Unknown

    CVE-2025-57824

    Last Modified: 21 Aug 2025

    Not used

    Published: 20 Aug 2025
    7.3
    High

    CVE-2025-8612

    Last Modified: 3 Sept 2025

    AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. User interaction on the part of an administrator is needed additionally. The specific flaw exists within the restore functionality. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27059.

    Published: 20 Aug 2025
    4.9
    Medium

    CVE-2025-20345

    Last Modified: 15 Apr 2026

    A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privileged, remote attacker to view sensitive information in a system log file. This vulnerability is due to insufficient masking of sensitive information before it is written to system log files. An attacker could exploit this vulnerability by accessing logs on an affected system. A successful exploit could allow the attacker to view sensitive information that should be restricted. 

    Published: 20 Aug 2025
    6.5
    Medium

    CVE-2025-20269

    Last Modified: 10 Sept 2025

    A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the underlying file system on an affected device. This vulnerability is due to insufficient input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface on an affected device. A successful exploit could allow the attacker to access sensitive files from the affected device.

    Published: 20 Aug 2025
    4.9
    Medium

    CVE-2025-20131

    Last Modified: 18 Sept 2026

    A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload using the Cisco ISE GUI. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2025-8611

    Last Modified: 22 Aug 2025

    AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DaoService service, which listens on TCP port 9074 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-26158.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2025-8610

    Last Modified: 25 Aug 2025

    AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the StorageNode service, which listens on TCP port 9075 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-26156.

    Published: 20 Aug 2025
    8.4
    High

    CVE-2010-20042

    Last Modified: 15 Jul 2026

    Xion Audio Player versions 1.0.126 and prior are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Exception Handler (SEH) chain, allowing an attacker to hijack execution flow and run arbitrary code.

    Published: 20 Aug 2025
    8.5
    High

    CVE-2011-10025

    Last Modified: 15 Apr 2026

    Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2011-10026

    Last Modified: 7 Apr 2026

    Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

    Published: 20 Aug 2025
    8.6
    High

    CVE-2011-10022

    Last Modified: 15 Apr 2026

    SPlayer version 3.7 and earlier is vulnerable to a stack-based buffer overflow when processing HTTP responses containing an overly long Content-Type header. The vulnerability occurs due to improper bounds checking on the header value, allowing an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code. Exploitation requires the victim to open a media file that triggers an HTTP request to a malicious server, which responds with a crafted Content-Type header.

    Published: 20 Aug 2025
    8.7
    High

    CVE-2011-10029

    Last Modified: 15 Apr 2026

    Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

    Published: 20 Aug 2025
    8.7
    High

    CVE-2012-10061

    Last Modified: 15 Apr 2026

    Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

    Published: 20 Aug 2025
    8.7
    High

    CVE-2011-10028

    Last Modified: 15 Apr 2026

    The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2010-20103

    Last Modified: 7 Apr 2026

    A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

    Published: 20 Aug 2025
    8.7
    High

    CVE-2010-10014

    Last Modified: 15 Apr 2026

    Odin Secure FTP <= 4.1 is vulnerable to a stack-based buffer overflow when parsing directory listings received in response to an FTP LIST command. A malicious FTP server can send an overly long filename in the directory listing, which overflows a fixed-size stack buffer in the client and overwrites the Structured Exception Handler (SEH). This allows remote attackers to execute arbitrary code on the client system.

    Published: 20 Aug 2025
    8.4
    High

    CVE-2011-10023

    Last Modified: 26 May 2026

    MJM QuickPlayer (also known as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is achieved via a crafted payload that bypasses DEP and ASLR protections using ROP techniques, and requires user interaction to open the file.

    Published: 20 Aug 2025
    8.4
    High

    CVE-2011-10024

    Last Modified: 15 Apr 2026

    MJM Core Player (likely now referred to as MJM Player) 2011 is vulnerable to a stack-based buffer overflow when parsing specially crafted .s3m music files. The vulnerability arises from improper bounds checking in the file parser, allowing an attacker to overwrite memory on the stack and execute arbitrary code. Exploitation is triggered when a user opens a malicious .s3m file, and the exploit bypasses DEP and ASLR protections using a ROP chain.

    Published: 20 Aug 2025
    8.4
    High

    CVE-2011-10021

    Last Modified: 15 Apr 2026

    Magix Musik Maker 16 is vulnerable to a stack-based buffer overflow due to improper handling of .mmm arrangement files. The vulnerability arises from an unsafe strcpy() operation that fails to validate input length, allowing attackers to overwrite the Structured Exception Handler (SEH). By crafting a malicious .mmm file, an attacker can trigger the overflow when the file is opened, potentially leading to arbitrary code execution. This vulnerability was remediated in version 17.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2010-20049

    Last Modified: 15 Apr 2026

    LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured Exception Handler (SEH) chain. This allows an attacker operating a malicious FTP server to execute arbitrary code on the victim’s machine when the file is listed or downloaded.

    Published: 20 Aug 2025