CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2025-36116

    Last Modified: 18 Aug 2025

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.

    Published: 23 Jul 2025
    Unknown

    CVE-2025-8086

    Last Modified: 6 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 23 Jul 2025
    8.7
    High

    CVE-2010-10012

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker can escape the web root and access sensitive files outside of the intended directory.

    Published: 23 Jul 2025
    9.3
    Critical

    CVE-2015-10141

    Last Modified: 15 Apr 2026

    An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugger protocol commands without authentication. An attacker can send a crafted eval command over this interface to execute arbitrary PHP code, which may invoke system-level functions such as system() or passthru(). This results in full compromise of the host under the privileges of the web server user.

    Published: 23 Jul 2025
    8.5
    High

    CVE-2016-15045

    Last Modified: 15 Apr 2026

    A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbitrary code execution as root.

    Published: 23 Jul 2025
    9.3
    Critical

    CVE-2017-20198

    Last Modified: 15 Apr 2026

    The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers. Due to improper restriction of volume mount configurations, attackers can deploy a container that mounts the host's root filesystem (/) with read/write privileges. When using a malicious Docker image, the attacker can write to /etc/cron.d/ on the host, achieving arbitrary code execution with root privileges. This impacts any system where the Docker daemon honors Marathon container configurations without policy enforcement.

    Published: 23 Jul 2025
    8.7
    High

    CVE-2018-25113

    Last Modified: 15 Apr 2026

    An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remote attackers to read arbitrary files on the underlying system by sending a crafted request to the /exportFile endpoint using the UID parameter. Successful exploitation can reveal sensitive files accessible by the web server user.

    Published: 23 Jul 2025
    9.3
    Critical

    CVE-2018-25114

    Last Modified: 15 Apr 2026

    A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An unauthenticated attacker can invoke install_4.php, submit crafted POST data, and inject arbitrary PHP code into the configure.php file. When the application later includes this file, the injected payload is executed, resulting in full server-side compromise.

    Published: 23 Jul 2025
    9.3
    Critical

    CVE-2022-4978

    Last Modified: 28 Jul 2026

    Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same network can issue a sequence of keystroke commands to launch a system shell and execute arbitrary commands, resulting in full system compromise.

    Published: 23 Jul 2025
    6.3
    Medium

    CVE-2025-54090

    Last Modified: 4 Nov 2025

    A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

    Published: 23 Jul 2025
    9.1
    Critical

    CVE-2025-40599

    Last Modified: 6 Nov 2025

    An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative privileges can exploit this flaw to upload arbitrary files to the system, potentially leading to remote code execution.

    Published: 23 Jul 2025
    6.5
    Medium

    CVE-2025-4411

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom Informatics PACS-ACSS allows Cross-Site Scripting (XSS). This issue affects PACS-ACSS: before 16.05.2025.

    Published: 23 Jul 2025
    7
    High

    CVE-2024-12310

    Last Modified: 15 Apr 2026

    A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already logged-in autologon account due to insufficient handling of keyboard shortcuts. This issue affects Imprivata Enterprise Access Management versions 5.3 through 24.2.

    Published: 23 Jul 2025
    4.7
    Medium

    CVE-2025-4296

    Last Modified: 5 Jun 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This issue affects B2B: before 04.06.2025.

    Published: 23 Jul 2025
    7
    High

    CVE-2025-54297

    Last Modified: 15 Apr 2026

    A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.

    Published: 23 Jul 2025
    9.3
    Critical

    CVE-2025-54294

    Last Modified: 15 Apr 2026

    A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

    Published: 23 Jul 2025
    5.1
    Medium

    CVE-2025-54295

    Last Modified: 15 Apr 2026

    A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

    Published: 23 Jul 2025
    5.5
    Medium

    CVE-2024-41750

    Last Modified: 18 Aug 2025

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

    Published: 23 Jul 2025
    7
    High

    CVE-2025-54296

    Last Modified: 15 Apr 2026

    A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

    Published: 23 Jul 2025
    6.2
    Medium

    CVE-2024-40682

    Last Modified: 18 Aug 2025

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.

    Published: 23 Jul 2025
    8.5
    High

    CVE-2025-50127

    Last Modified: 15 Apr 2026

    A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

    Published: 23 Jul 2025
    5.4
    Medium

    CVE-2024-40686

    Last Modified: 18 Aug 2025

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

    Published: 23 Jul 2025
    5.5
    Medium

    CVE-2024-41751

    Last Modified: 18 Aug 2025

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

    Published: 23 Jul 2025
    6.4
    Medium

    CVE-2025-27930

    Last Modified: 26 Feb 2026

    Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

    Published: 23 Jul 2025
    4.8
    Medium

    CVE-2025-53882

    Last Modified: 15 Apr 2026

    A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes. This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-41687

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.

    Published: 23 Jul 2025
    8.8
    High

    CVE-2025-41684

    Last Modified: 15 Apr 2026

    An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).

    Published: 23 Jul 2025
    8.8
    High

    CVE-2025-41683

    Last Modified: 15 Apr 2026

    An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test).

    Published: 23 Jul 2025
    9.2
    Critical

    CVE-2025-8070

    Last Modified: 15 Apr 2026

    The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

    Published: 23 Jul 2025
    8.1
    High

    CVE-2025-31701

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.

    Published: 23 Jul 2025
    8.1
    High

    CVE-2025-31700

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.

    Published: 23 Jul 2025
    6.1
    Medium

    CVE-2025-6174

    Last Modified: 15 Apr 2026

    The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or any other user.

    Published: 23 Jul 2025
    8.8
    High

    CVE-2025-54439

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54438

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54444

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54443

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54442

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    8.8
    High

    CVE-2025-54441

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54440

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    8.1
    High

    CVE-2025-54447

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54446

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0

    Published: 23 Jul 2025
    8.2
    High

    CVE-2025-54445

    Last Modified: 15 Aug 2025

    Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54448

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    8.8
    High

    CVE-2025-54453

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    7.3
    High

    CVE-2025-54452

    Last Modified: 28 Jul 2025

    Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54451

    Last Modified: 26 Feb 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    7.2
    High

    CVE-2025-54450

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.8
    Critical

    CVE-2025-54449

    Last Modified: 26 Feb 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.1
    Critical

    CVE-2025-54455

    Last Modified: 26 Feb 2026

    Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025
    9.1
    Critical

    CVE-2025-54454

    Last Modified: 26 Feb 2026

    Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

    Published: 23 Jul 2025