Latest CVE Feed
-
2.7
LOWCVE-2025-69230
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be abl... Read more
Affected Products : aiohttp- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-69229
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of t... Read more
Affected Products : aiohttp- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-69228
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an application includes a h... Read more
Affected Products : aiohttp- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
6.6
MEDIUMCVE-2025-69227
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If optimizations are ... Read more
Affected Products : aiohttp- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
2.7
LOWCVE-2025-69225
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There is no known impact, but there is the possibility that t... Read more
Affected Products : aiohttp- Published: Jan. 06, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-69226
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path... Read more
Affected Products : aiohttp- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
6.3
MEDIUMCVE-2025-69224
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is inst... Read more
Affected Products : aiohttp- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Misconfiguration
-
9.3
CRITICALCVE-2026-0625
Multiple D-Link DSL gateway devices contain a command injection vulnerability in the dnscfg.cgi endpoint due to improper sanitization of user-supplied DNS configuration parameters. An unauthenticated remote attacker can inject and execute arbitrary shell ... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
8.7
HIGHCVE-2026-0621
Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2026-0605
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack ma... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2026-0588
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.php of the component API. This manipulation of the argument callback causes cross site scripting. The attac... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2026-0587
A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the component Cover Image Handler. The manipulation of the argument fengmian results in cross site scripting. The a... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2026-0569
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. T... Read more
Affected Products :- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2026-0565
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing manipulation of the argument del can lead to sql injection. The attack can be executed remot... Read more
Affected Products : content_management_system- Published: Jan. 02, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-69223
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed ... Read more
Affected Products : aiohttp- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-68953
Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization... Read more
Affected Products : frappe- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
5.2
MEDIUMCVE-2025-68454
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to ... Read more
Affected Products : craft_cms- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2025-68436
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously cr... Read more
Affected Products : craft_cms- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Authorization
-
9.2
CRITICALCVE-2025-68428
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the... Read more
Affected Products : jspdf- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
8.4
HIGHCVE-2025-67732
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potenti... Read more
Affected Products : dify- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Information Disclosure