CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-55156

    Last Modified: 15 Apr 2026

    pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-55150

    Last Modified: 15 Aug 2025

    Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF. This issue has been patched in version 1.1.0.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-55151

    Last Modified: 15 Aug 2025

    Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" functionality (/api/v1/convert/file/pdf) uses LibreOffice's unoconvert tool for conversion, and SSRF vulnerabilities exist during the conversion process. This issue has been patched in version 1.1.0.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-25235

    Last Modified: 15 Apr 2026

    Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.

    Published: 11 Aug 2025
    6.9
    Medium

    CVE-2025-54992

    Last Modified: 15 Apr 2026

    OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with GHSL-2025-024 allows unauthenticated attackers to exfiltrate information from the instance where the OpenKilda UI is running. This issue may lead to Information disclosure. This issue has been patched in version 1.164.0.

    Published: 11 Aug 2025
    8.5
    High

    CVE-2025-55012

    Last Modified: 15 Apr 2026

    Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a project-specific configuration file, leading to the execution of arbitrary commands on a victim's machine without the explicit approval that would otherwise be required. This vulnerability has been patched in version 0.197.3. A workaround for this issue involves either avoid sending prompts to the Agent Panel, or to limit the AI Agent's file system access.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-54878

    Last Modified: 27 Aug 2025

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow vulnerability exists in NASA CryptoLib version 1.4.0 and prior in the IV setup logic for telecommand frames. The problem arises from missing bounds checks when copying the Initialization Vector (IV) into a freshly allocated buffer. An attacker can supply a crafted TC frame that causes the library to write one byte past the end of the heap buffer, leading to heap corruption and undefined behaviour. An attacker supplying a malformed telecommand frame can corrupt heap memory. This leads to undefined behaviour, which could manifest itself as a crash (denial of service) or more severe exploitation. This issue has been patched in version 1.4.0.

    Published: 11 Aug 2025
    9.8
    Critical

    CVE-2024-32640

    Last Modified: 15 Apr 2026

    MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

    Published: 11 Aug 2025
    8.6
    High

    CVE-2025-40920

    Last Modified: 15 Apr 2026

    Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID returns v3 UUIDs, which are generated from known information and are unsuitable for security, as per RFC 9562. * The nonces should be generated from a strong cryptographic source, as per RFC 7616.

    Published: 11 Aug 2025
    4
    Medium

    CVE-2025-8285

    Last Modified: 24 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.

    Published: 11 Aug 2025
    7.5
    High

    CVE-2025-54525

    Last Modified: 24 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.

    Published: 11 Aug 2025
    7.2
    High

    CVE-2025-54478

    Last Modified: 24 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

    Published: 11 Aug 2025
    5.9
    Medium

    CVE-2025-54463

    Last Modified: 24 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

    Published: 11 Aug 2025
    5
    Medium

    CVE-2025-54458

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for a Confluence space the user does not have access to via the create subscription endpoint.

    Published: 11 Aug 2025
    4
    Medium

    CVE-2025-53910

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

    Published: 11 Aug 2025
    3.7
    Low

    CVE-2025-53857

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions endpoint.

    Published: 11 Aug 2025
    5.9
    Medium

    CVE-2025-53514

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

    Published: 11 Aug 2025
    7.5
    High

    CVE-2025-52931

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.

    Published: 11 Aug 2025
    3.7
    Low

    CVE-2025-49221

    Last Modified: 24 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without via API call to GET subscription endpoint.

    Published: 11 Aug 2025
    6.4
    Medium

    CVE-2025-48731

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for a Confluence space the user does not have access for via edit subscription endpoint.

    Published: 11 Aug 2025
    7.2
    High

    CVE-2025-44004

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription without proper authorization via API call to the create channel subscription endpoint.

    Published: 11 Aug 2025
    4
    Medium

    CVE-2025-44001

    Last Modified: 25 Sept 2025

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

    Published: 11 Aug 2025
    9.2
    Critical

    CVE-2025-7679

    Last Modified: 15 Apr 2026

    The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT

    Published: 11 Aug 2025
    8.2
    High

    CVE-2025-7677

    Last Modified: 15 Apr 2026

    A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. This issue affects all versions of ASPECT.

    Published: 11 Aug 2025
    Unknown

    CVE-2025-53191

    Last Modified: 21 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2025
    Unknown

    CVE-2025-53190

    Last Modified: 21 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2025
    Unknown

    CVE-2025-53189

    Last Modified: 21 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2025
    Unknown

    CVE-2025-53188

    Last Modified: 21 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2025
    5.4
    Medium

    CVE-2025-25229

    Last Modified: 15 Apr 2026

    Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources.

    Published: 11 Aug 2025
    7.5
    High

    CVE-2025-25231

    Last Modified: 15 Apr 2026

    Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

    Published: 11 Aug 2025
    8
    High

    CVE-2025-54063

    Last Modified: 2 Dec 2025

    Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a malicious website or embedding a specially crafted URL on any website. If a victim clicks the exploit link in their browser, the app’s custom URL handler is triggered, leading to remote code execution on the victim’s machine. This issue has been patched in version 1.5.1.

    Published: 11 Aug 2025
    9.3
    Critical

    CVE-2025-53187

    Last Modified: 15 Apr 2026

    Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01

    Published: 11 Aug 2025
    5.1
    Medium

    CVE-2025-8866

    Last Modified: 15 Apr 2026

    YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.

    Published: 11 Aug 2025
    9.4
    Critical

    CVE-2012-10040

    Last Modified: 15 Apr 2026

    Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute arbitrary commands as the openfiler user. Due to misconfigured sudoers, the openfiler user can escalate privileges to root via sudo /bin/bash without a password.

    Published: 11 Aug 2025
    9.4
    Critical

    CVE-2012-10039

    Last Modified: 15 Apr 2026

    ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code execution as the root user. ZEN Load Balancer is the predecessor of ZEVENET and SKUDONET. The affected versions (2.0 and 3.0-rc1) are no longer supported. SKUDONET CE is the current community-maintained successor.

    Published: 11 Aug 2025
    9.3
    Critical

    CVE-2012-10038

    Last Modified: 15 Apr 2026

    Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ directory and can be executed directly, resulting in remote code execution.

    Published: 11 Aug 2025
    9.3
    Critical

    CVE-2012-10037

    Last Modified: 15 Apr 2026

    PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authentication is required.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8859

    Last Modified: 23 Oct 2025

    A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    4.1
    Medium

    CVE-2025-8865

    Last Modified: 15 Apr 2026

    The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.

    Published: 11 Aug 2025
    2.1
    Low

    CVE-2025-8852

    Last Modified: 16 Sept 2025

    A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    4.8
    Medium

    CVE-2025-8851

    Last Modified: 30 Oct 2025

    A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.

    Published: 11 Aug 2025
    6.8
    Medium

    CVE-2025-8864

    Last Modified: 15 Apr 2026

    Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

    Published: 11 Aug 2025
    7
    High

    CVE-2025-8863

    Last Modified: 15 Apr 2026

    YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

    Published: 11 Aug 2025
    2
    Low

    CVE-2025-8847

    Last Modified: 11 Sept 2025

    A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of the argument noticeTitle/noticeContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    7
    High

    CVE-2025-8862

    Last Modified: 15 Apr 2026

    YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a version where this information is properly redacted.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8846

    Last Modified: 15 Sept 2025

    A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    4.8
    Medium

    CVE-2025-8672

    Last Modified: 12 Sept 2025

    MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously granted TCC permissions to access user's files in privacy-protected folders without triggering user prompts. Accessing other resources beyond previously granted TCC permissions will prompt the user for approval in the name of GIMP, potentially disguising attacker's malicious intent. This issue has been fixed in 3.1.4.2 version of GIMP.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8845

    Last Modified: 15 Sept 2025

    A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8844

    Last Modified: 15 Sept 2025

    A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025
    1.9
    Low

    CVE-2025-8843

    Last Modified: 15 Sept 2025

    A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

    Published: 11 Aug 2025