[GUEST ACCESS MODE: Data is scrambled or limited to provide examples. Make requests using your API key to unlock full data. Check https://lunarcrush.ai/auth for authentication information.]
@CVEnew
"CVE-2025-46385 CWE-918 Server-Side Request Forgery (SSRF)" @CVEnew on X 2025-07-20 15:15:40 UTC 55K followers, XXX engagements
"CVE-2025-7716 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS)" @CVEnew on X 2025-07-21 16:53:02 UTC 55K followers, XXX engagements
"CVE-2025-7867 A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9.0. Affected is an unknown function of the file /intranet/agenda.php of the component" @CVEnew on X 2025-07-20 04:28:07 UTC 55K followers, XXX engagements
"CVE-2025-7286 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:39 UTC 55K followers, XXX engagements
"CVE-2025-30661 An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local low-privileged user" @CVEnew on X 2025-07-11 15:53:39 UTC 55K followers, XXX engagements
"CVE-2025-7307 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:59 UTC 55K followers, XXX engagements
"CVE-2025-7962 In Jakarta Mail XXX it is possible to preform a SMTP Injection by utilizing ther and n UTF-8 characters to separate different messages" @CVEnew on X 2025-07-21 17:46:31 UTC 55K followers, XXX engagements
"CVE-2025-52374 Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.conf" @CVEnew on X 2025-07-21 16:21:15 UTC 55K followers, XXX engagements
"CVE-2025-6082 The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to and including XXX. This is due to insufficient protecti" @CVEnew on X 2025-07-22 09:47:58 UTC 55K followers, XXX engagements
"CVE-2025-52948 An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker in rare cases" @CVEnew on X 2025-07-11 15:53:38 UTC 55K followers, XXX engagements
"CVE-2025-7287 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:39 UTC 55K followers, XXX engagements
"CVE-2025-51396 A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload" @CVEnew on X 2025-07-21 19:15:54 UTC 55K followers, XXX engagements
"CVE-2025-52947 An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allow" @CVEnew on X 2025-07-11 15:53:38 UTC 55K followers, XXX engagements
"CVE-2025-7240 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2025-7261 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:45 UTC 55K followers, XXX engagements
"CVE-2025-7869 A vulnerability which was classified as problematic has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file intr" @CVEnew on X 2025-07-20 05:29:33 UTC 55K followers, XXX engagements
"CVE-2025-7222 Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte" @CVEnew on X 2025-07-21 20:18:52 UTC 55K followers, XXX engagements
"CVE-2025-7291 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:38 UTC 55K followers, XXX engagements
"CVE-2025-7227 INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec" @CVEnew on X 2025-07-21 20:18:51 UTC 55K followers, XXX engagements
"CVE-2025-7279 IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:41 UTC 55K followers, XXX engagements
"CVE-2025-36062 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of unencrypted network traffic" @CVEnew on X 2025-07-21 18:54:51 UTC 55K followers, XXX engagements
"CVE-2012-10020 The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to and includ" @CVEnew on X 2025-07-22 03:09:38 UTC 55K followers, XXX engagements
"CVE-2025-7926 A vulnerability which was classified as problematic was found in PHPGurukul Online Banquet Booking System XXX. This affects an unknown part of the file /admin/booking" @CVEnew on X 2025-07-21 14:19:15 UTC 55K followers, XXX engagements
"CVE-2025-54122 Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy hand" @CVEnew on X 2025-07-21 21:16:26 UTC 55K followers, XXX engagements
"CVE-2025-4130 Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025" @CVEnew on X 2025-07-21 14:19:14 UTC 55K followers, XXX engagements
"CVE-2025-7275 IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:42 UTC 55K followers, XXX engagements
"CVE-2025-7877 A vulnerability which was classified as critical has been found in Metasoft MetaCRM up to 6.4.2. This issue affects some unknown processing of the file sendfile" @CVEnew on X 2025-07-20 08:47:04 UTC 55K followers, XXX engagements
"CVE-2025-7925 A vulnerability which was classified as problematic has been found in PHPGurukul Online Banquet Booking System XXX. Affected by this issue is some unknown functionali" @CVEnew on X 2025-07-21 13:28:30 UTC 55K followers, XXX engagements
"CVE-2025-7911 A vulnerability classified as critical was found in D-Link DI-8100 XXX. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhtt" @CVEnew on X 2025-07-20 22:53:44 UTC 55K followers, XXX engagements
"CVE-2025-51397 A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via" @CVEnew on X 2025-07-21 19:15:54 UTC 55K followers, XXX engagements
"CVE-2025-7859 A vulnerability classified as critical was found in code-projects Church Donation System XXX. This vulnerability affects unknown code of the file /members/update_passwo" @CVEnew on X 2025-07-20 01:21:36 UTC 55K followers, XXX engagements
"CVE-2025-7298 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 21:35:02 UTC 55K followers, XXX engagements
"CVE-2025-54128 HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below the NodeJS version of HAX CMS has a disabled Conte" @CVEnew on X 2025-07-21 21:16:26 UTC 55K followers, XXX engagements
"CVE-2025-4570 An insecure sensitive key storage issue was found in MyASUS.potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain se" @CVEnew on X 2025-07-21 08:24:49 UTC 55K followers, XXX engagements
"CVE-2025-43977 The application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction b" @CVEnew on X 2025-07-21 15:46:11 UTC 55K followers, XXX engagements
"CVE-2025-4129 Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.0" @CVEnew on X 2025-07-21 14:19:14 UTC 55K followers, XXX engagements
"CVE-2025-7486 The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to and including XXXXXX due to insufficient" @CVEnew on X 2025-07-21 22:41:16 UTC 55K followers, XXX engagements
"CVE-2025-7854 A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation o" @CVEnew on X 2025-07-19 20:55:08 UTC 55K followers, XXX engagements
"CVE-2025-7276 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:41 UTC 55K followers, XXX engagements
"CVE-2025-52964 A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based at" @CVEnew on X 2025-07-11 15:53:36 UTC 55K followers, XXX engagements
"CVE-2025-6831 The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to and including 4" @CVEnew on X 2025-07-22 03:09:38 UTC 55K followers, XXX engagements
"CVE-2025-44655 In TOTOLink A7100RU V7.4 A950RG V5.9 and T10 V5.9 the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system file" @CVEnew on X 2025-07-21 16:21:15 UTC 55K followers, XXX engagements
"CVE-2025-7920 WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability allowing unauthenticated remote attackers to execute arbitrar" @CVEnew on X 2025-07-21 07:49:23 UTC 55K followers, XXX engagements
"CVE-2025-7928 A vulnerability was found in code-projects Church Donation System XXX and classified as critical. This issue affects some unknown processing of the file /members/edit_u" @CVEnew on X 2025-07-21 15:17:54 UTC 55K followers, XXX engagements
"CVE-2025-8037 Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the S" @CVEnew on X 2025-07-22 21:35:27 UTC 55K followers, XXX engagements
"CVE-2025-41678 A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement" @CVEnew on X 2025-07-21 09:51:08 UTC 55K followers, XXX engagements
"CVE-2025-51471 Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via" @CVEnew on X 2025-07-22 18:54:34 UTC 55K followers, XXX engagements
"CVE-2025-7939 A vulnerability was found in jerryshensjf JPACookieShop JPA XXX. It has been classified as critical. Affected is the function addGoods of the file GoodsController" @CVEnew on X 2025-07-21 21:16:26 UTC 55K followers, XXX engagements
"CVE-2025-7919 WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability allowing unauthenticated remote attackers to inject arbitrary SQL commands to" @CVEnew on X 2025-07-21 06:56:16 UTC 55K followers, XXX engagements
"CVE-2025-38351 In the Linux kernel the following vulnerability has been resolved: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush In KVM guests with Hyper-V hy" @CVEnew on X 2025-07-19 12:29:04 UTC 55K followers, XXX engagements
"CVE-2025-7305 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:59 UTC 55K followers, XXX engagements
"CVE-2025-7290 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:38 UTC 55K followers, XXX engagements
"CVE-2025-7888 A vulnerability was found in TDuckCloud tduck-platform XXX and classified as critical. This issue affects the function UserFormDataMapper of the file src/main/java/com/" @CVEnew on X 2025-07-20 13:09:07 UTC 55K followers, XXX engagements
"CVE-2025-53475 A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires" @CVEnew on X 2025-07-11 13:46:17 UTC 55K followers, XXX engagements
"CVE-2025-7236 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2025-52949 An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a l" @CVEnew on X 2025-07-11 15:53:38 UTC 55K followers, XXX engagements
"CVE-2025-7248 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:46 UTC 55K followers, XXX engagements
"CVE-2025-7258 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:45 UTC 55K followers, XXX engagements
"CVE-2025-7369 The WP Shortcodes Plugin Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 7.4.2. This is due" @CVEnew on X 2025-07-21 07:49:22 UTC 55K followers, XXX engagements
"CVE-2023-52672 In the Linux kernel the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add general notificatio" @CVEnew on X 2024-05-17 19:51:18 UTC 55K followers, XXX engagements
"CVE-2016-15043 The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to and incl" @CVEnew on X 2025-07-19 09:51:15 UTC 55K followers, XXX engagements
"CVE-2025-36106 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then" @CVEnew on X 2025-07-21 18:54:51 UTC 55K followers, XXX engagements
"CVE-2025-4040 Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation.This issue affects Automatic St" @CVEnew on X 2025-07-21 13:28:30 UTC 55K followers, XXX engagements
"CVE-2025-49087 In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4 a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mod" @CVEnew on X 2025-07-20 18:50:37 UTC 55K followers, XXX engagements
"CVE-2025-7895 A vulnerability which was classified as critical was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/contro" @CVEnew on X 2025-07-20 14:52:33 UTC 55K followers, XXX engagements
"CVE-2025-54319 An issue was discovered in Westermo WeOS X (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information via system logging" @CVEnew on X 2025-07-20 20:54:14 UTC 55K followers, XXX engagements
"CVE-2025-7264 IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:44 UTC 55K followers, XXX engagements
"CVE-2025-7237 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:46 UTC 55K followers, XXX engagements
"CVE-2025-46123 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279 where the authent" @CVEnew on X 2025-07-21 15:17:54 UTC 55K followers, XXX engagements
"CVE-2025-7300 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:01 UTC 55K followers, XXX engagements
"CVE-2025-5994 A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also v" @CVEnew on X 2025-07-16 19:15:30 UTC 55K followers, XXX engagements
"CVE-2025-44658 In Netgear RAX30 V1.0.10.94 a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker m" @CVEnew on X 2025-07-21 15:57:55 UTC 55K followers, XXX engagements
"CVE-2025-52521 Trend Micro Security XXXX (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally d" @CVEnew on X 2025-07-11 13:46:29 UTC 55K followers, XXX engagements
"CVE-2015-10134 The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to and including 2.7.10. via the download_backup_file function. This" @CVEnew on X 2025-07-19 09:51:16 UTC 55K followers, XXX engagements
"CVE-2025-52986 A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a loc" @CVEnew on X 2025-07-11 15:53:34 UTC 55K followers, XXX engagements
"CVE-2025-7250 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2025-7238 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:45 UTC 55K followers, XXX engagements
"CVE-2025-46383 CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')" @CVEnew on X 2025-07-20 14:52:33 UTC 55K followers, XXX engagements
"CVE-2025-50151 File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users ar" @CVEnew on X 2025-07-21 09:51:07 UTC 55K followers, XXX engagements
"CVE-2025-7655 The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to and including 1" @CVEnew on X 2025-07-19 03:55:51 UTC 55K followers, XXX engagements
"CVE-2025-7818 A vulnerability was found in PHPGurukul Apartment Visitors Management System XXX and classified as problematic. Affected by this issue is some unknown functionality of" @CVEnew on X 2025-07-19 13:07:50 UTC 55K followers, XXX engagements
"CVE-2025-7427 Uncontrolled Search Path Element in Arm Development Studio before 2025may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to lo" @CVEnew on X 2025-07-22 10:18:25 UTC 55K followers, XXX engagements
"CVE-2025-7913 A vulnerability which was classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQTT Service" @CVEnew on X 2025-07-20 23:52:52 UTC 55K followers, XXX engagements
"CVE-2025-51864 A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat through 2025-05-27 allowing attackers to hijack accounts through sto" @CVEnew on X 2025-07-22 15:18:01 UTC 55K followers, XXX engagements
"CVE-2025-7906 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/jav" @CVEnew on X 2025-07-20 19:50:37 UTC 55K followers, XXX engagements
"CVE-2025-51472 Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values" @CVEnew on X 2025-07-22 20:45:15 UTC 55K followers, XXX engagements
"CVE-2025-7855 A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromqossetting of the file /goform/qossetting. T" @CVEnew on X 2025-07-19 21:15:14 UTC 55K followers, XXX engagements
"CVE-2025-7893 A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xm" @CVEnew on X 2025-07-20 13:55:57 UTC 55K followers, XXX engagements
"CVE-2025-24937 File contents could be read from the local file system by an attacker. Additionally malicious code could be inserted in the file leading to a full compromise of the" @CVEnew on X 2025-07-21 06:56:15 UTC 55K followers, XXX engagements
"CVE-2025-43976 The application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user" @CVEnew on X 2025-07-21 15:46:11 UTC 55K followers, XXX engagements
"CVE-2025-7936 A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as critical. Affected by this vulnerability is" @CVEnew on X 2025-07-21 19:50:43 UTC 55K followers, XXX engagements
"CVE-2025-7278 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:41 UTC 55K followers, XXX engagements
"CVE-2025-52577 A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an" @CVEnew on X 2025-07-11 13:46:16 UTC 55K followers, XXX engagements
"CVE-2025-6982 Use of Hard-coded Credentials in TP-Link Archer C50 V3( = 180703)/V4( = 250117 )/V5( = 200407 )allows attackers to decrypt the config.xml files" @CVEnew on X 2025-07-16 20:45:03 UTC 55K followers, 1035 engagements
"CVE-2025-43720 Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role revealing the" @CVEnew on X 2025-07-21 17:17:42 UTC 55K followers, XXX engagements
"CVE-2025-7871 A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulat" @CVEnew on X 2025-07-20 06:51:34 UTC 55K followers, XXX engagements
"CVE-2025-7273 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:42 UTC 55K followers, XXX engagements
"CVE-2025-7324 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:45:27 UTC 55K followers, XXX engagements
"CVE-2025-7323 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:45:27 UTC 55K followers, XXX engagements
"CVE-2025-7909 A vulnerability was found in D-Link DIR-513 XXX. It has been rated as critical. Affected by this issue is the function sprintf of the file /goform/formLanSetupRouterSet" @CVEnew on X 2025-07-20 21:51:51 UTC 55K followers, XXX engagements
"CVE-2025-7263 IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:44 UTC 55K followers, XXX engagements
"CVE-2025-7856 A vulnerability was found in PHPGurukul Apartment Visitors Management System XXX. It has been declared as problematic. Affected by this vulnerability is an unknown func" @CVEnew on X 2025-07-19 21:51:06 UTC 55K followers, XXX engagements
"CVE-2025-7863 A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function redirectUrl of the file src/main/java/c" @CVEnew on X 2025-07-20 03:23:20 UTC 55K followers, XXX engagements
"CVE-2025-7836 A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the file /h" @CVEnew on X 2025-07-19 17:15:25 UTC 55K followers, XXX engagements
"CVE-2025-7242 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2020-26799 A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data" @CVEnew on X 2025-07-21 19:15:54 UTC 55K followers, XXX engagements
"CVE-2025-51865 Ai2 playground web service LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR) allowing attackers to gain s" @CVEnew on X 2025-07-22 15:18:01 UTC 55K followers, XXX engagements
"CVE-2025-7857 A vulnerability was found in PHPGurukul Apartment Visitors Management System XXX. It has been rated as problematic. Affected by this issue is some unknown functionality" @CVEnew on X 2025-07-19 23:17:42 UTC 55K followers, XXX engagements
"CVE-2025-41679 An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing" @CVEnew on X 2025-07-21 09:51:08 UTC 55K followers, XXX engagements
"CVE-2025-41674 A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements" @CVEnew on X 2025-07-21 09:51:09 UTC 55K followers, XXX engagements
"CVE-2025-46118 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279 where hard-coded c" @CVEnew on X 2025-07-21 14:49:28 UTC 55K followers, XXX engagements
"CVE-2025-4049 Use of hard-coded the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.T" @CVEnew on X 2025-07-21 08:24:50 UTC 55K followers, XXX engagements
"CVE-2025-7288 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:39 UTC 55K followers, XXX engagements
"CVE-2025-7285 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:38 UTC 55K followers, XXX engagements
"CVE-2025-7901 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index" @CVEnew on X 2025-07-20 15:35:12 UTC 55K followers, XXX engagements
"CVE-2025-54316 An issue was discovered in Logpoint before 7.6.0. When creating reports attackers can create custom Jinja templates that chained built-in filter functions to generat" @CVEnew on X 2025-07-20 19:13:19 UTC 55K followers, XXX engagements
"CVE-2025-7600 A vulnerability which was classified as critical was found in PHPGurukul Online Library Management System XXX. This affects an unknown part of the file /admin/student" @CVEnew on X 2025-07-14 11:53:09 UTC 55K followers, XXX engagements
"CVE-2025-6549 An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker to reach the J" @CVEnew on X 2025-07-11 15:53:34 UTC 55K followers, XXX engagements
"CVE-2025-7837 A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT" @CVEnew on X 2025-07-19 17:15:24 UTC 55K followers, XXX engagements
"CVE-2025-7829 A vulnerability was found in code-projects Church Donation System XXX. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t" @CVEnew on X 2025-07-19 13:55:22 UTC 55K followers, XXX engagements
"CVE-2025-7873 A vulnerability was found in Metasoft MetaCRM up to 6.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file" @CVEnew on X 2025-07-20 07:15:20 UTC 55K followers, XXX engagements
"CVE-2025-41673 A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements us" @CVEnew on X 2025-07-21 09:51:10 UTC 55K followers, XXX engagements
"CVE-2025-8031 The username:password part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects F" @CVEnew on X 2025-07-22 21:35:27 UTC 55K followers, XXX engagements
"CVE-2025-41458 Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the apps filesyste" @CVEnew on X 2025-07-21 11:32:58 UTC 55K followers, XXX engagements
"CVE-2025-7312 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 21:34:58 UTC 55K followers, XXX engagements
"CVE-2025-51868 Insecure Direct Object Reference (IDOR) vulnerability in Dippy v2 allows attackers to gain sensitive information via the conversation_id parameter to" @CVEnew on X 2025-07-21 21:35:02 UTC 55K followers, XXX engagements
"CVE-2025-6187 The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1.3.7 through 1.7.9" @CVEnew on X 2025-07-22 09:47:57 UTC 55K followers, XXX engagements
"CVE-2025-7289 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:39 UTC 55K followers, XXX engagements
"CVE-2025-7325 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:45:26 UTC 55K followers, XXX engagements
"CVE-2025-52982 An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated network-based a" @CVEnew on X 2025-07-11 15:53:35 UTC 55K followers, XXX engagements
"CVE-2025-52981 An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600 SRX2300" @CVEnew on X 2025-07-11 15:53:35 UTC 55K followers, XXX engagements
"CVE-2025-7224 INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected" @CVEnew on X 2025-07-21 20:18:51 UTC 55K followers, XXX engagements
"CVE-2025-7918 WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability allowing unauthenticated remote attackers to inject arbitrary SQL commands to" @CVEnew on X 2025-07-21 06:56:16 UTC 55K followers, XXX engagements
"CVE-2025-6213 The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.1.1 via the 'nppp_preload_cache_on_upd" @CVEnew on X 2025-07-22 09:47:57 UTC 55K followers, XXX engagements
"CVE-2025-7392 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue" @CVEnew on X 2025-07-21 16:53:02 UTC 55K followers, XXX engagements
"CVE-2025-7914 A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component" @CVEnew on X 2025-07-21 03:21:44 UTC 55K followers, XXX engagements
"CVE-2025-7235 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2025-7915 A vulnerability was found in Chanjet CRM XXX and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of the" @CVEnew on X 2025-07-21 03:21:43 UTC 55K followers, XXX engagements
"CVE-2025-7309 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:58 UTC 55K followers, XXX engagements
"CVE-2025-52955 An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to" @CVEnew on X 2025-07-11 15:53:37 UTC 55K followers, XXX engagements
"CVE-2025-6377 A remote code execution security issue exists in the Rockwell AutomationArena.A crafted DOE file can force Arena Simulation to write beyond the boundaries of an all" @CVEnew on X 2025-07-10 15:45:56 UTC 55K followers, XXX engagements
"CVE-2025-25257 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability CWE-89 in Fortinet FortiWeb version 7.6.0 through 7.6.3 7.4.0" @CVEnew on X 2025-07-17 15:45:51 UTC 55K followers, XXX engagements
"CVE-2025-7935 A vulnerability which was classified as critical was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. Affected is the function SysLo" @CVEnew on X 2025-07-21 19:15:54 UTC 55K followers, XXX engagements
"CVE-2025-7304 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:00 UTC 55K followers, XXX engagements
"CVE-2025-7880 A vulnerability was found in Metasoft MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality of the file /business/co" @CVEnew on X 2025-07-20 09:21:09 UTC 55K followers, XXX engagements
"CVE-2025-7270 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:42 UTC 55K followers, XXX engagements
"CVE-2025-7226 INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected" @CVEnew on X 2025-07-21 20:18:51 UTC 55K followers, XXX engagements
"CVE-2025-7394 In the OpenSSL compatibility layer implementation the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned fr" @CVEnew on X 2025-07-18 22:55:44 UTC 55K followers, XXX engagements
"CVE-2025-7929 A vulnerability was found in code-projects Church Donation System XXX. It has been classified as critical. Affected is an unknown function of the file /members/edit_Mem" @CVEnew on X 2025-07-21 15:57:55 UTC 55K followers, XXX engagements
"CVE-2025-36057 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not neede" @CVEnew on X 2025-07-21 18:54:50 UTC 55K followers, XXX engagements
"CVE-2025-47917 Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509" @CVEnew on X 2025-07-20 19:13:18 UTC 55K followers, XXX engagements
"CVE-2025-46267 Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited the product's hidden debug function may be enabled by a remote attacker who can log in" @CVEnew on X 2025-07-22 09:47:56 UTC 55K followers, XXX engagements
"CVE-2025-7269 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:43 UTC 55K followers, XXX engagements
"CVE-2025-51869 Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id thread_id and mes" @CVEnew on X 2025-07-21 19:32:41 UTC 55K followers, XXX engagements
"CVE-2025-46117 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279 where a hidden de" @CVEnew on X 2025-07-21 14:49:27 UTC 55K followers, XXX engagements
"CVE-2025-5681 Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 23" @CVEnew on X 2025-07-21 11:32:57 UTC 55K followers, XXX engagements
"CVE-2025-7318 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:16:27 UTC 55K followers, XXX engagements
"CVE-2025-52362 Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl" @CVEnew on X 2025-07-21 19:15:56 UTC 55K followers, XXX engagements
"CVE-2025-7834 A vulnerability which was classified as problematic was found in PHPGurukul Complaint Management System XXX. Affected is an unknown function. The manipulation leads t" @CVEnew on X 2025-07-19 16:49:19 UTC 55K followers, XXX engagements
"CVE-2015-10140 The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions allowing any authenticated users such as subscriber to upload and" @CVEnew on X 2025-07-22 13:56:12 UTC 55K followers, XXX engagements
"CVE-2025-7292 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:02 UTC 55K followers, XXX engagements
"CVE-2025-54121 Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit designed for building async web services in Python. In versions 0.47.1 and" @CVEnew on X 2025-07-21 20:45:26 UTC 55K followers, XXX engagements
"CVE-2025-7293 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:02 UTC 55K followers, XXX engagements
"CVE-2025-53528 Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions 5.4.3 and below the version parameter of the "/docs" endpo" @CVEnew on X 2025-07-21 20:45:25 UTC 55K followers, XXX engagements
"CVE-2025-7904 A vulnerability which was classified as critical was found in itsourcecode Insurance Management System XXX. This affects an unknown part of the file /insertNominee.ph" @CVEnew on X 2025-07-20 17:14:14 UTC 55K followers, XXX engagements
"CVE-2025-52988 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolv" @CVEnew on X 2025-07-11 15:53:34 UTC 55K followers, XXX engagements
"CVE-2025-7230 INVT VT-Designer PM3 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i" @CVEnew on X 2025-07-21 20:18:50 UTC 55K followers, XXX engagements
"CVE-2025-52953 An Expected Behavior Violationvulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent" @CVEnew on X 2025-07-11 15:53:36 UTC 55K followers, XXX engagements
"CVE-2025-7371 Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to th" @CVEnew on X 2025-07-22 15:58:10 UTC 55K followers, XXX engagements
"CVE-2025-7254 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:47 UTC 55K followers, XXX engagements
"CVE-2025-7243 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:48 UTC 55K followers, XXX engagements
"CVE-2025-7932 A vulnerability classified as critical has been found in D-Link DIR817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manipulation l" @CVEnew on X 2025-07-21 17:46:32 UTC 55K followers, XXX engagements
"CVE-2025-38352 In the Linux kernel the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exi" @CVEnew on X 2025-07-22 08:52:59 UTC 55K followers, XXX engagements
"CVE-2025-44651 In TRENDnet TPL-430AP FW1.0 the USERLIMIT_GLOBAL option is set to X in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are conn" @CVEnew on X 2025-07-21 15:46:11 UTC 55K followers, XXX engagements
"CVE-2025-7319 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 21:16:27 UTC 55K followers, XXX engagements
"CVE-2025-6235 In ExtremeControl before 25.5.12 a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from impro" @CVEnew on X 2025-07-21 14:19:14 UTC 55K followers, XXX engagements
"CVE-2025-7233 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inf" @CVEnew on X 2025-07-21 20:18:48 UTC 55K followers, XXX engagements
"CVE-2025-52963 An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local low-privileged attacker to bring down an interface l" @CVEnew on X 2025-07-11 15:53:36 UTC 55K followers, XXX engagements
"CVE-2025-52984 A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-bas" @CVEnew on X 2025-07-11 15:53:35 UTC 55K followers, XXX engagements
"CVE-2025-41676 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession" @CVEnew on X 2025-07-21 09:51:09 UTC 55K followers, XXX engagements
"CVE-2025-7255 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:46 UTC 55K followers, XXX engagements
"CVE-2025-7876 A vulnerability classified as critical was found in Metasoft MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of the file download.jsp. Th" @CVEnew on X 2025-07-20 07:51:33 UTC 55K followers, XXX engagements
"CVE-2025-41675 A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of sp" @CVEnew on X 2025-07-21 09:51:09 UTC 55K followers, XXX engagements
"CVE-2025-7308 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:59 UTC 55K followers, XXX engagements
"CVE-2025-7885 A vulnerability which was classified as problematic has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the comp" @CVEnew on X 2025-07-20 11:29:50 UTC 55K followers, XXX engagements
"CVE-2025-7229 INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec" @CVEnew on X 2025-07-21 20:18:50 UTC 55K followers, XXX engagements
"CVE-2025-54317 An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template whi" @CVEnew on X 2025-07-20 19:13:19 UTC 55K followers, XXX engagements
"CVE-2025-53515 A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authe" @CVEnew on X 2025-07-11 13:46:16 UTC 55K followers, XXX engagements
"CVE-2025-7317 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:56 UTC 55K followers, XXX engagements
"CVE-2025-7322 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:45:27 UTC 55K followers, XXX engagements
"CVE-2025-2301 Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers.This issue affects" @CVEnew on X 2025-07-21 11:53:15 UTC 55K followers, XXX engagements
"CVE-2025-36107 IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data" @CVEnew on X 2025-07-21 18:54:51 UTC 55K followers, XXX engagements
"CVE-2025-7645 The Extensions For CF7 (Contact form X Database Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f" @CVEnew on X 2025-07-22 06:55:35 UTC 55K followers, XXX engagements
"CVE-2025-7889 A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidMan" @CVEnew on X 2025-07-20 13:09:07 UTC 55K followers, XXX engagements
"CVE-2025-51463 Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitt" @CVEnew on X 2025-07-22 15:46:18 UTC 55K followers, XXX engagements
"CVE-2025-7900 The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1" @CVEnew on X 2025-07-22 10:49:25 UTC 55K followers, XXX engagements
"CVE-2025-54127 HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below the NodeJS version of HAX CMS uses an ins" @CVEnew on X 2025-07-21 21:16:26 UTC 55K followers, XXX engagements
"CVE-2025-51398 A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTM" @CVEnew on X 2025-07-21 19:15:55 UTC 55K followers, XXX engagements
"CVE-2025-53770 Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that a" @CVEnew on X 2025-07-20 01:21:35 UTC 55K followers, XXX engagements
"CVE-2025-52951 A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic to an interface to effec" @CVEnew on X 2025-07-11 15:53:37 UTC 55K followers, XXX engagements
"CVE-2025-51401 A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML vi" @CVEnew on X 2025-07-21 19:15:55 UTC 55K followers, XXX engagements
"CVE-2025-7866 A vulnerability was found in Portabilis i-Educar 2.9.0. It has been rated as problematic. This issue affects some unknown processing of the file /intranet/educar_defici" @CVEnew on X 2025-07-20 04:28:07 UTC 55K followers, XXX engagements
"CVE-2025-46704 A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authent" @CVEnew on X 2025-07-11 13:46:17 UTC 55K followers, XXX engagements
"CVE-2025-30762 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 14.1.1.0.0 an" @CVEnew on X 2025-07-15 19:44:31 UTC 55K followers, XXX engagements
"CVE-2025-7251 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:50 UTC 55K followers, XXX engagements
"CVE-2025-51400 A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML" @CVEnew on X 2025-07-21 19:15:55 UTC 55K followers, XXX engagements
"CVE-2025-54134 HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below the HAX CMS NodeJS application crashes when an aut" @CVEnew on X 2025-07-21 21:16:25 UTC 55K followers, XXX engagements
"CVE-2025-7343 The SFT developed by Digiwin has a SQL Injection vulnerability allowing unauthenticated remote attackers to inject arbitrary SQL commands to read modify and delete d" @CVEnew on X 2025-07-21 07:24:39 UTC 55K followers, XXX engagements
"CVE-2025-7840 A vulnerability was found in Campcodes Online Movie Theater Seat Reservation System XXX. It has been classified as problematic. This affects an unknown part of the file" @CVEnew on X 2025-07-19 18:50:08 UTC 55K followers, XXX engagements
"CVE-2025-7284 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:38 UTC 55K followers, XXX engagements
"CVE-2025-7875 A vulnerability classified as critical has been found in Metasoft MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. The manipulation leads" @CVEnew on X 2025-07-20 07:32:41 UTC 55K followers, XXX engagements
"CVE-2015-10135 The WPshop X E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions befo" @CVEnew on X 2025-07-19 09:51:15 UTC 55K followers, XXX engagements
"CVE-2025-7524 A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstec" @CVEnew on X 2025-07-13 09:42:45 UTC 55K followers, XXX engagements
"CVE-2025-7862 A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file" @CVEnew on X 2025-07-20 03:23:20 UTC 55K followers, XXX engagements
"CVE-2025-7831 A vulnerability classified as critical has been found in code-projects Church Donation System XXX. This affects an unknown part of the file /members/Tithes.php. The man" @CVEnew on X 2025-07-19 15:35:08 UTC 55K followers, XXX engagements
"CVE-2025-7241 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:49 UTC 55K followers, XXX engagements
"CVE-2025-52989 An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local authenticated attacker with high pr" @CVEnew on X 2025-07-11 15:53:34 UTC 55K followers, XXX engagements
"CVE-2025-7249 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:48 UTC 55K followers, XXX engagements
"CVE-2025-7724 An unauthenticated OS command injection vulnerability existsin VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build" @CVEnew on X 2025-07-22 21:35:28 UTC 55K followers, XXX engagements
"CVE-2025-7297 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:01 UTC 55K followers, XXX engagements
"CVE-2025-7897 A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/con" @CVEnew on X 2025-07-20 15:15:39 UTC 55K followers, XXX engagements
"CVE-2025-7878 A vulnerability which was classified as critical was found in Metasoft MetaCRM up to 6.4.2. Affected is an unknown function of the file /common/jsp/upload2.jsp" @CVEnew on X 2025-07-20 08:47:04 UTC 55K followers, XXX engagements
"CVE-2025-52958 A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of JuniperNetworks Junos OS and Junos OS Evolved allows an adjacentunauthenticatedattacke" @CVEnew on X 2025-07-11 15:53:37 UTC 55K followers, XXX engagements
"CVE-2025-7274 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:41 UTC 55K followers, XXX engagements
"CVE-2025-7942 A vulnerability has been found in PHPGurukul Taxi Stand Management System XXX and classified as problematic. Affected by this vulnerability is an unknown functionality" @CVEnew on X 2025-07-21 22:41:16 UTC 55K followers, XXX engagements
"CVE-2025-7948 A vulnerability classified as problematic was found in jshERP up to XXX. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/update" @CVEnew on X 2025-07-22 03:09:39 UTC 55K followers, XXX engagements
"CVE-2025-7283 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:40 UTC 55K followers, XXX engagements
"CVE-2025-7931 A vulnerability was found in code-projects Church Donation System XXX. It has been rated as critical. Affected by this issue is some unknown functionality of the file /" @CVEnew on X 2025-07-21 16:53:03 UTC 55K followers, XXX engagements
"CVE-2025-7934 A vulnerability which was classified as critical has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. This issue affects the fu" @CVEnew on X 2025-07-21 19:15:54 UTC 55K followers, XXX engagements
"CVE-2025-7354 The WP Shortcodes Plugin Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to and" @CVEnew on X 2025-07-21 07:49:22 UTC 55K followers, XXX engagements
"CVE-2025-54313 eslint-config-prettier 8.10.1 9.1.1 10.1.6 and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install" @CVEnew on X 2025-07-19 16:49:19 UTC 55K followers, XXX engagements
"CVE-2025-41677 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession" @CVEnew on X 2025-07-21 09:51:09 UTC 55K followers, XXX engagements
"CVE-2025-6720 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to" @CVEnew on X 2025-07-19 05:56:01 UTC 55K followers, XXX engagements
"CVE-2025-7583 A vulnerability has been found in PHPGurukul Online Fire Reporting System XXX and classified as critical. This vulnerability affects unknown code of the file /admin/all" @CVEnew on X 2025-07-14 07:20:51 UTC 55K followers, XXX engagements
"CVE-2025-7266 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:43 UTC 55K followers, XXX engagements
"CVE-2025-52575 EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authent" @CVEnew on X 2025-07-21 18:23:52 UTC 55K followers, XXX engagements
"CVE-2025-50063 Vulnerability in Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u451 and 8u451-perf. Easily exploitable vulnerabilit" @CVEnew on X 2025-07-15 19:44:30 UTC 55K followers, XXX engagements
"CVE-2025-53771 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a" @CVEnew on X 2025-07-20 22:37:33 UTC 55K followers, XXX engagements
"CVE-2025-7947 A vulnerability classified as critical has been found in jshERP up to XXX. Affected is an unknown function of the file /user/delete of the component Account Handler. Th" @CVEnew on X 2025-07-22 03:09:39 UTC 55K followers, XXX engagements
"CVE-2025-44647 In TRENDnet TEW-WLC100P 2.03b03 the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file so that IKE Respon" @CVEnew on X 2025-07-21 15:57:55 UTC 55K followers, XXX engagements
"CVE-2025-28243 An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component" @CVEnew on X 2025-07-11 15:53:41 UTC 55K followers, XXX engagements
"CVE-2025-7314 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:57 UTC 55K followers, XXX engagements
"CVE-2025-7927 A vulnerability has been found in PHPGurukul Online Banquet Booking System XXX and classified as critical. This vulnerability affects unknown code of the file /admin/vi" @CVEnew on X 2025-07-21 14:49:27 UTC 55K followers, XXX engagements
"CVE-2025-7256 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:46 UTC 55K followers, XXX engagements
"CVE-2025-7941 A vulnerability which was classified as problematic was found in PHPGurukul Time Table Generator System XXX. Affected is an unknown function of the file /admin/profil" @CVEnew on X 2025-07-21 22:41:16 UTC 55K followers, XXX engagements
"CVE-2025-7916 WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability allowing unauthenticated remote attackers to execute arbitrary code on the ser" @CVEnew on X 2025-07-21 06:28:14 UTC 55K followers, XXX engagements
"CVE-2025-7868 A vulnerability classified as problematic was found in Portabilis i-Educar 2.9.0. Affected by this vulnerability is an unknown functionality of the file /intranet/educa" @CVEnew on X 2025-07-20 05:00:56 UTC 55K followers, XXX engagements
"CVE-2025-7715 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attributes allows Cross-Site Scripting (XSS).This iss" @CVEnew on X 2025-07-21 16:53:02 UTC 55K followers, XXX engagements
"CVE-2025-6721 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() fun" @CVEnew on X 2025-07-19 05:56:01 UTC 55K followers, XXX engagements
"CVE-2025-7912 A vulnerability which was classified as critical has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the compon" @CVEnew on X 2025-07-20 23:16:58 UTC 55K followers, XXX engagements
"CVE-2025-7917 WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability allowing remote attackers with administrator privileges to upload and" @CVEnew on X 2025-07-21 06:56:16 UTC 55K followers, XXX engagements
"CVE-2025-54314 Thor before 1.4.0 can construct an unsafe shell command from library input" @CVEnew on X 2025-07-20 03:23:21 UTC 55K followers, XXX engagements
"CVE-2025-36845 An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a" @CVEnew on X 2025-07-21 18:23:53 UTC 55K followers, XXX engagements
"CVE-2025-7870 A vulnerability which was classified as problematic was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endp" @CVEnew on X 2025-07-20 05:50:13 UTC 55K followers, XXX engagements
"CVE-2025-7692 The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 1.0.5. This is due to the olws_handle_verify_" @CVEnew on X 2025-07-22 09:47:58 UTC 55K followers, XXX engagements
"CVE-2025-7933 A vulnerability classified as critical was found in Campcodes Sales and Inventory System XXX. This vulnerability affects unknown code of the file /pages/settings_update" @CVEnew on X 2025-07-21 18:54:51 UTC 55K followers, XXX engagements
"CVE-2025-54129 HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below the application returns a" @CVEnew on X 2025-07-21 21:16:25 UTC 55K followers, XXX engagements
"CVE-2025-7930 A vulnerability was found in code-projects Church Donation System XXX. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t" @CVEnew on X 2025-07-21 16:21:15 UTC 55K followers, XXX engagements
"CVE-2025-7393 Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0" @CVEnew on X 2025-07-21 16:53:02 UTC 55K followers, XXX engagements
"CVE-2025-7344 The EAI developed by Digiwin has a Privilege Escalation vulnerability allowing remote attackers with regular privileges to elevate their privileges to administrator le" @CVEnew on X 2025-07-21 07:24:39 UTC 55K followers, XXX engagements
"CVE-2025-7268 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:43 UTC 55K followers, XXX engagements
"CVE-2025-27210 An incomplete fix has been identified for CVE-2025-23084 in Node.js specifically affecting Windows device names like CON PRN and AUX. This vulnerability affect" @CVEnew on X 2025-07-18 23:16:18 UTC 55K followers, XXX engagements
"CVE-2024-56220 Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notificatio" @CVEnew on X 2024-12-31 10:14:56 UTC 55K followers, XXX engagements
"CVE-2025-8033 The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability affects Firefox 141" @CVEnew on X 2025-07-22 21:35:26 UTC 55K followers, XXX engagements
"CVE-2025-54310 qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp" @CVEnew on X 2025-07-18 19:41:53 UTC 55K followers, XXX engagements
"CVE-2025-7908 A vulnerability was found in D-Link DI-8100 XXX. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file /ddns.aspopt=add" @CVEnew on X 2025-07-20 21:15:02 UTC 55K followers, XXX engagements
"CVE-2024-13973 A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than XXXX MR1 (21.0.1) can potentially lead to administrators achieving arbitrar" @CVEnew on X 2025-07-21 14:19:14 UTC 55K followers, XXX engagements
"CVE-2025-52950 AMissing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive" @CVEnew on X 2025-07-11 15:53:38 UTC 55K followers, XXX engagements
"CVE-2025-5957 The Guest Support Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ch" @CVEnew on X 2025-07-08 05:18:03 UTC 55K followers, XXX engagements
"CVE-2025-53832 Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vulnerability which e" @CVEnew on X 2025-07-21 20:45:25 UTC 55K followers, XXX engagements
"CVE-2025-52954 A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolvedallows a local low-privileged user to" @CVEnew on X 2025-07-11 15:53:37 UTC 55K followers, XXX engagements
"CVE-2025-46116 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279 where an authenti" @CVEnew on X 2025-07-21 14:49:27 UTC 55K followers, XXX engagements
"CVE-2025-7717 Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0 from 2.0.0 before 2.0.1" @CVEnew on X 2025-07-21 16:53:01 UTC 55K followers, XXX engagements
"CVE-2025-8029 Thunderbird executed javascript: URLs when used in object and embed tags. This vulnerability affects Firefox XXX Firefox ESR XXXXXX Firefox ESR XXXXX Thu" @CVEnew on X 2025-07-22 21:35:27 UTC 55K followers, XXX engagements
"CVE-2025-52946 A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker sending a BG" @CVEnew on X 2025-07-11 15:53:38 UTC 55K followers, XXX engagements
"CVE-2025-44650 In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2 the USERLIMIT_GLOBAL option is set to X in the bftpd.conf configuration file. This can cause DoS attacks" @CVEnew on X 2025-07-21 15:46:11 UTC 55K followers, XXX engagements
"CVE-2025-28244 Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage" @CVEnew on X 2025-07-11 15:53:42 UTC 55K followers, XXX engagements
"CVE-2012-10019 The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3" @CVEnew on X 2025-07-19 09:51:15 UTC 55K followers, XXX engagements
"CVE-2025-46382 CWE-200 Exposure of Sensitive Information to an Unauthorized Actor" @CVEnew on X 2025-07-20 14:52:33 UTC 55K followers, XXX engagements
"CVE-2025-52985 A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to by" @CVEnew on X 2025-07-11 15:53:34 UTC 55K followers, XXX engagements
"CVE-2025-7231 INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec" @CVEnew on X 2025-07-21 20:18:50 UTC 55K followers, XXX engagements
"CVE-2025-7874 A vulnerability was found in Metasoft MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /env" @CVEnew on X 2025-07-20 07:15:19 UTC 55K followers, XXX engagements
"CVE-2025-28245 Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body" @CVEnew on X 2025-07-11 15:53:42 UTC 55K followers, XXX engagements
"CVE-2025-7246 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:47 UTC 55K followers, XXX engagements
"CVE-2025-7832 A vulnerability classified as critical was found in code-projects Church Donation System XXX. This vulnerability affects unknown code of the file /members/offering.php" @CVEnew on X 2025-07-19 15:35:08 UTC 55K followers, XXX engagements
"CVE-2025-53397 A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057 which could allow a reflected cross-site scripting (XSS) attack. By exploiting this f" @CVEnew on X 2025-07-11 13:46:18 UTC 55K followers, XXX engagements
"CVE-2025-7510 A vulnerability has been found in code-projects Modern Bag XXX and classified as critical. This vulnerability affects unknown code of the file /admin/productadd_back.ph" @CVEnew on X 2025-07-13 01:19:57 UTC 55K followers, XXX engagements
"CVE-2015-10139 The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for" @CVEnew on X 2025-07-19 11:40:50 UTC 55K followers, XXX engagements
"CVE-2025-32744 Dell AppSync version(s) 4.6.0.0 contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could poten" @CVEnew on X 2025-07-21 16:53:03 UTC 55K followers, XXX engagements
"CVE-2025-50069 Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploitable vulnerabili" @CVEnew on X 2025-07-15 19:44:28 UTC 55K followers, XXX engagements
"CVE-2025-46122 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 where the authenticated diagnostics API endpoint /admin/_cmdstat.j" @CVEnew on X 2025-07-21 15:17:54 UTC 55K followers, XXX engagements
"CVE-2025-7313 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:57 UTC 55K followers, XXX engagements
"CVE-2025-8038 Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox XXX Firefox ESR XXXXX Thunderbird XXX and Th" @CVEnew on X 2025-07-22 21:35:26 UTC 55K followers, XXX engagements
"CVE-2025-7833 A vulnerability which was classified as critical has been found in code-projects Church Donation System XXX. This issue affects some unknown processing of the file /m" @CVEnew on X 2025-07-19 15:54:15 UTC 55K followers, XXX engagements
"CVE-2025-7281 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:40 UTC 55K followers, XXX engagements
"CVE-2025-7302 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:00 UTC 55K followers, XXX engagements
"CVE-2025-7853 A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. The manipu" @CVEnew on X 2025-07-19 19:50:35 UTC 55K followers, XXX engagements
"CVE-2025-48301 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid YaySMTP allows SQL Injection. Th" @CVEnew on X 2025-07-16 10:48:46 UTC 55K followers, XXX engagements
"CVE-2025-7257 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:46 UTC 55K followers, XXX engagements
"CVE-2025-41237 VMware ESXiWorkstation and Fusioncontain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write.A malicious" @CVEnew on X 2025-07-15 18:54:28 UTC 55K followers, XXX engagements
"CVE-2025-52372 An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer" @CVEnew on X 2025-07-21 16:21:15 UTC 55K followers, XXX engagements
"CVE-2025-4685 The Gutentor Gutenberg Blocks Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of mu" @CVEnew on X 2025-07-21 07:49:22 UTC 55K followers, XXX engagements
"CVE-2025-7280 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:40 UTC 55K followers, XXX engagements
"CVE-2025-50130 A heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC CO. LTD. Opening V9 files or X1 files specia" @CVEnew on X 2025-07-08 14:39:29 UTC 55K followers, XXX engagements
"CVE-2025-7228 INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec" @CVEnew on X 2025-07-21 20:18:51 UTC 55K followers, XXX engagements
"CVE-2025-53378 A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely t" @CVEnew on X 2025-07-11 13:46:28 UTC 55K followers, XXX engagements
"CVE-2025-7311 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:58 UTC 55K followers, XXX engagements
"CVE-2025-7271 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:42 UTC 55K followers, XXX engagements
"CVE-2025-51464 Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to t" @CVEnew on X 2025-07-22 17:46:32 UTC 55K followers, XXX engagements
"CVE-2025-46121 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 where the functions stamgr_cfg_adpt_addStaFavourite and stamgr_c" @CVEnew on X 2025-07-21 15:17:54 UTC 55K followers, XXX engagements
"CVE-2025-41459 Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attacke" @CVEnew on X 2025-07-21 11:32:58 UTC 55K followers, XXX engagements
"CVE-2025-7940 A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functional" @CVEnew on X 2025-07-21 21:34:56 UTC 55K followers, XXX engagements
"CVE-2025-7924 A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System XXX. Affected by this vulnerability is an unknown functionality of the f" @CVEnew on X 2025-07-21 11:32:57 UTC 55K followers, XXX engagements
"CVE-2025-7272 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:42 UTC 55K followers, XXX engagements
"CVE-2025-6997 The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to and including 2.35.1.1 due to insuffi" @CVEnew on X 2025-07-19 08:47:55 UTC 55K followers, XXX engagements
"CVE-2025-7382 A command injection vulnerability in WebAdmin of Sophos Firewall versions older than XXXX MR2 (21.0.2)can lead to adjacent attackers achieving pre-auth code execution" @CVEnew on X 2025-07-21 14:19:15 UTC 55K followers, XXX engagements
"CVE-2025-7816 A vulnerability which was classified as problematic was found in PHPGurukul Apartment Visitors Management System XXX. Affected is an unknown function of the file /vis" @CVEnew on X 2025-07-19 10:55:00 UTC 55K followers, XXX engagements
"CVE-2025-41681 A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content" @CVEnew on X 2025-07-21 09:51:08 UTC 55K followers, XXX engagements
"CVE-2025-51462 Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafte" @CVEnew on X 2025-07-22 20:45:15 UTC 55K followers, XXX engagements
"CVE-2024-6107 Due to insufficient verification an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in" @CVEnew on X 2025-07-21 09:25:18 UTC 55K followers, XXX engagements
"CVE-2025-7830 A vulnerability was found in code-projects Church Donation System XXX. It has been rated as critical. Affected by this issue is some unknown functionality of the file /" @CVEnew on X 2025-07-19 14:52:34 UTC 55K followers, XXX engagements
"CVE-2025-7247 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:47 UTC 55K followers, XXX engagements
"CVE-2025-7225 INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected" @CVEnew on X 2025-07-21 20:18:51 UTC 55K followers, XXX engagements
"CVE-2025-7872 A vulnerability was found in Portabilis i-Diario 1.5.0 and classified as problematic. This issue affects some unknown processing of the file /justificativas-de-falta. T" @CVEnew on X 2025-07-20 06:51:34 UTC 55K followers, XXX engagements
"CVE-2025-7687 The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including XXX. This is due to missing or i" @CVEnew on X 2025-07-22 09:47:58 UTC 55K followers, XXX engagements
"CVE-2025-7860 A vulnerability which was classified as critical has been found in code-projects Church Donation System XXX. This issue affects some unknown processing of the file /m" @CVEnew on X 2025-07-20 01:21:36 UTC 55K followers, XXX engagements
"CVE-2025-44649 In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03 the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase X exposes i" @CVEnew on X 2025-07-21 16:53:04 UTC 55K followers, XXX engagements
"CVE-2024-13974 A business logic vulnerability in the Up2Date component of Sophos Firewall older than version XXXX MR1 (20.0.1) can lead to attackers controlling the firewalls DNS e" @CVEnew on X 2025-07-21 14:19:15 UTC 55K followers, XXX engagements
"CVE-2025-7838 A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System XXX and classified as critical. This vulnerability affects unknown code of the" @CVEnew on X 2025-07-19 17:36:37 UTC 55K followers, XXX engagements
"CVE-2025-7903 A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Imag" @CVEnew on X 2025-07-20 17:14:14 UTC 55K followers, XXX engagements
"CVE-2015-10138 The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server" @CVEnew on X 2025-07-19 11:40:50 UTC 55K followers, XXX engagements
"CVE-2025-34100 An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder XXX file manager and its use of the jQuery File Upload plu" @CVEnew on X 2025-07-11 13:46:25 UTC 55K followers, XXX engagements
"CVE-2025-7294 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:01 UTC 55K followers, XXX engagements
"CVE-2025-53472 WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in WebGUI. If exploite" @CVEnew on X 2025-07-22 09:47:57 UTC 55K followers, XXX engagements
"CVE-2025-7907 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/re" @CVEnew on X 2025-07-20 20:43:37 UTC 55K followers, XXX engagements
"CVE-2025-7723 A command injection vulnerability exists that can be exploited after authenticationin VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P" @CVEnew on X 2025-07-22 21:35:28 UTC 55K followers, XXX engagements
"CVE-2025-7262 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:44 UTC 55K followers, XXX engagements
"CVE-2025-7945 A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /go" @CVEnew on X 2025-07-21 23:52:56 UTC 55K followers, XXX engagements
"CVE-2025-7815 A vulnerability which was classified as problematic has been found in PHPGurukul Apartment Visitors Management System XXX. This issue affects some unknown processing" @CVEnew on X 2025-07-19 09:51:15 UTC 55K followers, XXX engagements
"CVE-2025-36603 Dell AppSync version(s) 4.6.0.0 contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could p" @CVEnew on X 2025-07-21 16:53:04 UTC 55K followers, XXX engagements
"CVE-2025-41442 A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057 which could allow a reflected cross-site scripting (XSS) attack. By manipulating cert" @CVEnew on X 2025-07-11 13:46:17 UTC 55K followers, XXX engagements
"CVE-2025-7953 A vulnerability which was classified as problematic has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processing of the file publi" @CVEnew on X 2025-07-22 04:52:47 UTC 55K followers, XXX engagements
"CVE-2025-7295 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:01 UTC 55K followers, XXX engagements
"CVE-2025-7316 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:57 UTC 55K followers, XXX engagements
"CVE-2025-7949 A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the" @CVEnew on X 2025-07-22 03:09:39 UTC 55K followers, XXX engagements
"CVE-2025-7223 INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected" @CVEnew on X 2025-07-21 20:18:52 UTC 55K followers, XXX engagements
"CVE-2025-7883 A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file AiStoneServiceMyControlCen" @CVEnew on X 2025-07-20 11:14:04 UTC 55K followers, XXX engagements
"CVE-2025-1469 Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 11" @CVEnew on X 2025-07-21 08:55:36 UTC 55K followers, XXX engagements
"CVE-2025-7910 A vulnerability classified as critical has been found in D-Link DIR-513 XXXX. This affects the function sprintf of the file /goform/formSetWanNonLogin of the component" @CVEnew on X 2025-07-20 22:37:34 UTC 55K followers, XXX engagements
"CVE-2025-7858 A vulnerability classified as problematic has been found in PHPGurukul Apartment Visitors Management System XXX. This affects an unknown part of the file /admin-profile" @CVEnew on X 2025-07-19 23:54:19 UTC 55K followers, XXX engagements
"CVE-2025-46384 CWE-434 Unrestricted Upload of File with Dangerous Type" @CVEnew on X 2025-07-20 14:52:33 UTC 55K followers, XXX engagements
"CVE-2025-7282 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:40 UTC 55K followers, XXX engagements
"CVE-2025-7685 The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including XXX. This is due to missing or incorrect" @CVEnew on X 2025-07-22 09:47:57 UTC 55K followers, XXX engagements
"CVE-2025-8015 The WP Shortcodes Plugin Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded image's 'Title' and 'Slide link' fields" @CVEnew on X 2025-07-22 15:17:59 UTC 55K followers, XXX engagements
"CVE-2025-7267 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:43 UTC 55K followers, XXX engagements
"CVE-2025-7315 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:57 UTC 55K followers, XXX engagements
"CVE-2025-7861 A vulnerability which was classified as critical was found in code-projects Church Donation System XXX. Affected is an unknown function of the file /members/search.ph" @CVEnew on X 2025-07-20 01:21:36 UTC 55K followers, XXX engagements
"CVE-2025-7898 A vulnerability was found in Codecanyon iDentSoft XXX. It has been classified as critical. This affects an unknown part of the file /clinica/profile/updateSetting of th" @CVEnew on X 2025-07-20 15:35:13 UTC 55K followers, XXX engagements
"CVE-2025-6376 A remote code execution security issue exists in the Rockwell AutomationArena.A crafted DOE file can force Arena Simulation to write beyond the boundaries of an all" @CVEnew on X 2025-07-10 15:45:56 UTC 55K followers, XXX engagements
"CVE-2025-7938 A vulnerability was found in jerryshensjf JPACookieShop JPA XXX and classified as critical. This issue affects the function updateGoods of the file GoodsController" @CVEnew on X 2025-07-21 21:34:58 UTC 55K followers, XXX engagements
"CVE-2025-7260 IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:45 UTC 55K followers, XXX engagements
"CVE-2025-4569 An insecure sensitive key storage issue was found in MyASUS.potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain se" @CVEnew on X 2025-07-21 08:24:50 UTC 55K followers, XXX engagements
"CVE-2025-24938 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administra" @CVEnew on X 2025-07-21 06:56:15 UTC 55K followers, XXX engagements
"CVE-2025-53509 A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker" @CVEnew on X 2025-07-11 13:46:16 UTC 55K followers, XXX engagements
"CVE-2025-49656 Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users ar" @CVEnew on X 2025-07-21 09:51:09 UTC 55K followers, 1709 engagements
"CVE-2025-7881 A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the componen" @CVEnew on X 2025-07-20 09:51:51 UTC 55K followers, XXX engagements
"CVE-2025-7884 A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the componen" @CVEnew on X 2025-07-20 11:29:50 UTC 55K followers, XXX engagements
"CVE-2025-7303 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:00 UTC 55K followers, XXX engagements
"CVE-2025-7296 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:01 UTC 55K followers, XXX engagements
"CVE-2025-52837 Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker" @CVEnew on X 2025-07-11 13:46:29 UTC 55K followers, XXX engagements
"CVE-2025-53519 A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057 which could allow a reflected cross-site scripting (XSS) attack. By manipulating spec" @CVEnew on X 2025-07-11 13:46:18 UTC 55K followers, XXX engagements
"CVE-2025-53825 Dokploy is a free self-hostable Platform as a Service (PaaS). Prior to version 0.24.3 an unauthenticated preview deployment vulnerability in Dokploy allows any user" @CVEnew on X 2025-07-14 22:55:21 UTC 55K followers, 1420 engagements
"CVE-2025-7879 A vulnerability has been found in Metasoft MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file m" @CVEnew on X 2025-07-20 09:21:09 UTC 55K followers, XXX engagements
"CVE-2025-7234 IrfanView CADImage Plugin CGM File Parsing Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:48 UTC 55K followers, XXX engagements
"CVE-2025-7277 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:41 UTC 55K followers, XXX engagements
"CVE-2025-7943 A vulnerability was found in PHPGurukul Taxi Stand Management System XXX and classified as problematic. Affected by this issue is some unknown functionality of the file" @CVEnew on X 2025-07-21 23:16:27 UTC 55K followers, XXX engagements
"CVE-2025-48965 Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than ze" @CVEnew on X 2025-07-20 18:21:12 UTC 55K followers, XXX engagements
"CVE-2025-54071 RomM (ROM Manager) allows users to scan enrich browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below an" @CVEnew on X 2025-07-21 20:45:26 UTC 55K followers, XXX engagements
"CVE-2025-7265 IrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:44 UTC 55K followers, XXX engagements
"CVE-2024-55040 Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET re" @CVEnew on X 2025-07-21 15:46:10 UTC 55K followers, XXX engagements
"CVE-2015-10133 The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to and including 2.1.2 via the Path to header value. This allows authen" @CVEnew on X 2025-07-19 09:51:15 UTC 55K followers, XXX engagements
"CVE-2015-10137 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' func" @CVEnew on X 2025-07-22 03:09:38 UTC 55K followers, XXX engagements
"CVE-2025-7817 A vulnerability has been found in PHPGurukul Apartment Visitors Management System XXX and classified as problematic. Affected by this vulnerability is an unknown functi" @CVEnew on X 2025-07-19 11:50:31 UTC 55K followers, XXX engagements
"CVE-2015-10136 The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before XXX via the 'fileid' parameter. This allows unauthenticated attacker" @CVEnew on X 2025-07-19 09:51:16 UTC 55K followers, XXX engagements
"CVE-2025-24936 The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network st" @CVEnew on X 2025-07-21 06:56:15 UTC 55K followers, XXX engagements
"CVE-2025-7252 IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code" @CVEnew on X 2025-07-21 20:18:50 UTC 55K followers, XXX engagements
"CVE-2025-0664 A locally authenticated privileged user can craft a malicious OpenSSL configuration file potentially leading the agent to load an arbitrary local library. This may im" @CVEnew on X 2025-07-21 07:49:22 UTC 55K followers, XXX engagements
"CVE-2025-7864 A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main/java/com/jeesite/m" @CVEnew on X 2025-07-20 03:23:20 UTC 55K followers, XXX engagements
"CVE-2025-7886 A vulnerability which was classified as critical was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the fu" @CVEnew on X 2025-07-20 11:50:28 UTC 55K followers, XXX engagements
"CVE-2025-44657 In Linksys EA6350 V2.1.2 the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to sy" @CVEnew on X 2025-07-21 15:46:11 UTC 55K followers, XXX engagements
"CVE-2025-44652 In Netgear RAX30 V1.0.10.94_3 the USERLIMIT_GLOBAL option is set to X in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users" @CVEnew on X 2025-07-21 17:46:32 UTC 55K followers, XXX engagements
"CVE-2025-7899 The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download ofarbitraryfiles from the webserver. This issue affects powermail vers" @CVEnew on X 2025-07-22 10:49:25 UTC 55K followers, XXX engagements
"CVE-2025-7887 A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file The" @CVEnew on X 2025-07-20 11:50:28 UTC 55K followers, XXX engagements
"CVE-2025-5240 The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the type parameter in all versions up to and including 2" @CVEnew on X 2025-07-22 03:09:38 UTC 55K followers, XXX engagements
"CVE-2025-7301 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:35:00 UTC 55K followers, XXX engagements
"CVE-2025-44251 Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process" @CVEnew on X 2025-07-10 15:45:55 UTC 55K followers, XXX engagements
"CVE-2025-52952 An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN MPC1 through MPC9 l" @CVEnew on X 2025-07-11 15:53:36 UTC 55K followers, XXX engagements
"CVE-2025-7921 Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability allowing unauthenticated remote attackers to control the program's execution fl" @CVEnew on X 2025-07-21 07:24:39 UTC 55K followers, XXX engagements
"CVE-2025-30477 Dell PowerScale OneFS versions prior to 9.11.0.0 contains a use of a broken or risky cryptographic algorithm vulnerability. A high privileged attacker with remote a" @CVEnew on X 2025-07-21 16:53:03 UTC 55K followers, XXX engagements
"CVE-2025-7320 IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:16:27 UTC 55K followers, XXX engagements
"CVE-2025-48891 A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by" @CVEnew on X 2025-07-11 13:46:17 UTC 55K followers, XXX engagements
"CVE-2025-7299 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:45:26 UTC 55K followers, XXX engagements
"CVE-2025-44653 In H3C GR2200 MiniGR1A0V100R016 the USERLIMIT_GLOBAL option is set to X in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected" @CVEnew on X 2025-07-21 17:46:32 UTC 55K followers, XXX engagements
"CVE-2025-7244 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:47 UTC 55K followers, XXX engagements
"CVE-2025-7306 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:59 UTC 55K followers, XXX engagements
"CVE-2025-7819 A vulnerability was found in PHPGurukul Apartment Visitors Management System XXX. It has been classified as problematic. This affects an unknown part of the file /creat" @CVEnew on X 2025-07-19 13:07:49 UTC 55K followers, XXX engagements
"CVE-2025-46119 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.12.304 where an authenticated request to the management endpoint /admin/_cmdstat.jsp disclo" @CVEnew on X 2025-07-21 14:49:28 UTC 55K followers, XXX engagements
"CVE-2025-52373 Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailSer" @CVEnew on X 2025-07-21 16:21:15 UTC 55K followers, XXX engagements
"CVE-2025-7865 A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of the file src/main/" @CVEnew on X 2025-07-20 03:23:20 UTC 55K followers, XXX engagements
"CVE-2025-7905 A vulnerability has been found in itsourcecode Insurance Management System XXX and classified as critical. This vulnerability affects unknown code of the file /insertPa" @CVEnew on X 2025-07-20 19:28:05 UTC 55K followers, XXX engagements
"CVE-2025-44654 In Linksys E2500 3.0.04.002 the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files privile" @CVEnew on X 2025-07-21 17:46:32 UTC 55K followers, XXX engagements
"CVE-2025-36846 An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vuln" @CVEnew on X 2025-07-21 18:23:53 UTC 55K followers, XXX engagements
"CVE-2025-7902 A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/web/controller/syste" @CVEnew on X 2025-07-20 16:48:02 UTC 55K followers, XXX engagements
"CVE-2025-7896 A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/dele" @CVEnew on X 2025-07-20 15:15:40 UTC 55K followers, XXX engagements
"CVE-2025-5042 A maliciously crafted RFA file when parsed through Autodesk Revit can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to" @CVEnew on X 2025-07-22 16:52:59 UTC 55K followers, XXX engagements
"CVE-2025-7321 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:16:26 UTC 55K followers, XXX engagements
"CVE-2025-52983 A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based unauthenticated attacker to acc" @CVEnew on X 2025-07-11 15:53:35 UTC 55K followers, XXX engagements
"CVE-2025-7310 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 21:34:58 UTC 55K followers, XXX engagements
"CVE-2025-51482 Remote Code Execution in in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code" @CVEnew on X 2025-07-22 17:18:09 UTC 55K followers, XXX engagements
"CVE-2025-54082 marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0 a vulnerability was discovered in the marshmallow-packages/no" @CVEnew on X 2025-07-21 16:53:03 UTC 55K followers, XXX engagements
"CVE-2025-7239 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:45 UTC 55K followers, XXX engagements
"CVE-2025-46120 An issue was discovered in CommScope Ruckus Unleashed prior to 200.14.6.1.203 and in Ruckus ZoneDirector where a path-traversal flaw in the web interface lets the se" @CVEnew on X 2025-07-21 14:49:28 UTC 55K followers, XXX engagements
"CVE-2025-7882 A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the componen" @CVEnew on X 2025-07-20 10:42:56 UTC 55K followers, XXX engagements
"CVE-2025-7253 IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o" @CVEnew on X 2025-07-21 20:18:48 UTC 55K followers, XXX engagements
"CVE-2025-53503 Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro f" @CVEnew on X 2025-07-11 13:46:28 UTC 55K followers, XXX engagements
"CVE-2025-7946 A vulnerability was found in PHPGurukul Apartment Visitors Management System XXX. It has been rated as problematic. This issue affects some unknown processing of the fi" @CVEnew on X 2025-07-22 03:09:39 UTC 55K followers, XXX engagements
"CVE-2025-52980 A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated netwo" @CVEnew on X 2025-07-11 15:53:35 UTC 55K followers, XXX engagements
"CVE-2025-7894 A vulnerability which was classified as critical has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/age" @CVEnew on X 2025-07-20 14:14:55 UTC 55K followers, XXX engagements
"CVE-2025-52459 A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with" @CVEnew on X 2025-07-11 13:46:16 UTC 55K followers, XXX engagements
"CVE-2025-49888 Missing Authorization vulnerability in pimwick PW WooCommerce On Sale allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PW" @CVEnew on X 2025-07-16 19:15:34 UTC 55K followers, XXX engagements
"CVE-2025-51403 A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web s" @CVEnew on X 2025-07-21 19:15:55 UTC 55K followers, XXX engagements