CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-21165

    Last Modified: 11 Jul 2025

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-21166

    Last Modified: 11 Jul 2025

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-21167

    Last Modified: 11 Jul 2025

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-21164

    Last Modified: 11 Jul 2025

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7186

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-43580

    Last Modified: 15 Jul 2025

    Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could result in application denial-of-service. An attacker could leverage this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-43587

    Last Modified: 14 Jul 2025

    After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-47109

    Last Modified: 14 Jul 2025

    After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    8.2
    High

    CVE-2025-3648

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query requests to infer instance data that is not intended to be accessible to them. To assist customers in enhancing access controls, ServiceNow has introduced additional access control frameworks in Xanadu and Yokohama, such as Query ACLs, Security Data Filters and Deny-Unless ACLs. Additionally, in May 2025, ServiceNow delivered to customers a security update that is designed to enhance customer ACL configurations. Customers, please review the KB Articles in the References section.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7185

    Last Modified: 13 Jul 2025

    A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /approve.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    7.2
    High

    CVE-2025-6771

    Last Modified: 13 Jul 2025

    OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-0292

    Last Modified: 15 Jul 2025

    SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services.

    Published: 8 Jul 2025
    6.6
    Medium

    CVE-2025-0293

    Last Modified: 13 Jul 2025

    CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-5464

    Last Modified: 15 Jul 2025

    Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7184

    Last Modified: 13 Jul 2025

    A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unknown part of the file /user/teacher/books.php. The manipulation of the argument Search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.8
    Medium

    CVE-2025-43019

    Last Modified: 20 Jan 2026

    A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.

    Published: 8 Jul 2025
    7.2
    High

    CVE-2025-6770

    Last Modified: 13 Jul 2025

    OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-5463

    Last Modified: 15 Jul 2025

    Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.

    Published: 8 Jul 2025
    6.9
    Medium

    CVE-2025-53545

    Last Modified: 15 Apr 2026

    Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vulnerability is fixed in commit ddb439f8eb1816010f2ef653a908648b71f9bba8.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7183

    Last Modified: 13 Jul 2025

    A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/customer_account.php. The manipulation of the argument Customer leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    4.9
    Medium

    CVE-2025-5451

    Last Modified: 15 Jul 2025

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service.

    Published: 8 Jul 2025
    4.3
    Medium

    CVE-2025-2827

    Last Modified: 24 Aug 2025

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.

    Published: 8 Jul 2025
    6.3
    Medium

    CVE-2025-5450

    Last Modified: 15 Jul 2025

    Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-2793

    Last Modified: 24 Aug 2025

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-53480

    Last Modified: 15 Apr 2026

    The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit this by appending ?uselang=x-xss to the URL, causing reflected XSS when the UI renders affected message keys. This issue affects Mediawiki - CheckUser extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

    Published: 8 Jul 2025
    7.2
    High

    CVE-2025-7037

    Last Modified: 13 Jul 2025

    SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-53372

    Last Modified: 15 Apr 2026

    node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to execute arbitrary JavaScript. Prior to 1.3.0, a command injection vulnerability exists in the node-code-sandbox-mcp MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to child_process.execSync, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges on the host machine, bypassing the sandbox protection of running code inside docker. This vulnerability is fixed in 1.3.0.

    Published: 8 Jul 2025
    6.4
    Medium

    CVE-2025-3630

    Last Modified: 24 Aug 2025

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-6996

    Last Modified: 13 Jul 2025

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-6995

    Last Modified: 13 Jul 2025

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

    Published: 8 Jul 2025
    7.2
    High

    CVE-2024-52965

    Last Modified: 22 Jul 2025

    A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.

    Published: 8 Jul 2025
    2.7
    Low

    CVE-2025-24474

    Last Modified: 22 Jul 2025

    An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiAnalyzer 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; and FortiAnalyzer Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker with high privilege to extract database information via crafted requests.

    Published: 8 Jul 2025
    5.3
    Medium

    CVE-2024-55599

    Last Modified: 9 Jun 2026

    An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7182

    Last Modified: 9 Jul 2025

    A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/modules/subject/edit.php. The manipulation of the argument pre leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-7326

    Last Modified: 15 Apr 2026

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.

    Published: 8 Jul 2025
    Unknown

    CVE-2025-7356

    Last Modified: 30 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Jul 2025
    8.2
    High

    CVE-2025-36600

    Last Modified: 18 Aug 2025

    Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7181

    Last Modified: 8 Jul 2025

    A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The manipulation of the argument uploadedfile leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7180

    Last Modified: 8 Jul 2025

    A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7179

    Last Modified: 8 Jul 2025

    A vulnerability classified as critical was found in code-projects Library System 1.0. This vulnerability affects unknown code of the file /add-teacher.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    3.6
    Low

    CVE-2025-27613

    Last Modified: 15 Apr 2026

    Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

    Published: 8 Jul 2025
    8.6
    High

    CVE-2025-27614

    Last Modified: 15 Apr 2026

    Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

    Published: 8 Jul 2025
    5.6
    Medium

    CVE-2024-36357

    Last Modified: 15 Apr 2026

    A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-50130

    Last Modified: 15 Apr 2026

    A heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC CO., LTD. Opening V9 files or X1 files specially crafted by an attacker on the affected product may lead to arbitrary code execution.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-27061

    Last Modified: 11 Aug 2025

    Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-27058

    Last Modified: 21 Jul 2025

    Memory corruption while processing packet data with exceedingly large packet.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-27057

    Last Modified: 25 Sept 2025

    Transient DOS while handling beacon frames with invalid IE header length.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-27056

    Last Modified: 21 Jul 2025

    Memory corruption during sub-system restart while processing clean-up to free up resources.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-27055

    Last Modified: 11 Aug 2025

    Memory corruption during the image encoding process.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-27052

    Last Modified: 11 Aug 2025

    Memory corruption while processing data packets in diag received from Unix clients.

    Published: 8 Jul 2025