CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2025-68939

    Last Modified: 2 Jan 2026

    Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

    Published: 26 Dec 2025
    2
    Low

    CVE-2025-15095

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 26 Dec 2025
    2.1
    Low

    CVE-2025-15094

    Last Modified: 24 Feb 2026

    A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Login. Executing a manipulation of the argument redirectUrl can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 26 Dec 2025
    4.3
    Medium

    CVE-2025-68938

    Last Modified: 2 Jan 2026

    Gitea before 1.25.2 mishandles authorization for deletion of releases.

    Published: 26 Dec 2025
    2.1
    Low

    CVE-2025-15093

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected element is an unknown function of the file src/main/java/com/flycms/web/system/IndexAdminController.java of the component Admin Login. Performing a manipulation of the argument redirectUrl results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Dec 2025
    7.4
    High

    CVE-2025-15092

    Last Modified: 31 Dec 2025

    A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument remark leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 26 Dec 2025
    5.1
    Medium

    CVE-2025-65885

    Last Modified: 9 Jan 2026

    An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory.

    Published: 26 Dec 2025
    6.5
    Medium

    CVE-2025-66947

    Last Modified: 31 Dec 2025

    SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module.

    Published: 26 Dec 2025
    4.3
    Medium

    CVE-2025-66737

    Last Modified: 9 Jan 2026

    Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.

    Published: 26 Dec 2025
    6.5
    Medium

    CVE-2024-42718

    Last Modified: 31 Dec 2025

    A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

    Published: 26 Dec 2025
    7.5
    High

    CVE-2025-57403

    Last Modified: 9 Jan 2026

    Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.

    Published: 26 Dec 2025
    8.8
    High

    CVE-2025-66738

    Last Modified: 9 Jan 2026

    An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

    Published: 26 Dec 2025
    6.5
    Medium

    CVE-2025-67013

    Last Modified: 2 Jan 2026

    The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

    Published: 26 Dec 2025
    6.1
    Medium

    CVE-2025-67349

    Last Modified: 31 Dec 2025

    A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.

    Published: 26 Dec 2025
    7.5
    High

    CVE-2025-67015

    Last Modified: 2 Jan 2026

    Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

    Published: 26 Dec 2025
    7.5
    High

    CVE-2025-67014

    Last Modified: 9 Jan 2026

    Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint.

    Published: 26 Dec 2025
    9.8
    Critical

    CVE-2024-44065

    Last Modified: 31 Dec 2025

    Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

    Published: 26 Dec 2025
    5.5
    Medium

    CVE-2024-29720

    Last Modified: 9 Jan 2026

    An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function.

    Published: 26 Dec 2025
    7.5
    High

    CVE-2025-25341

    Last Modified: 31 Dec 2025

    A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).

    Published: 26 Dec 2025
    9.5
    Critical

    CVE-2025-68937

    Last Modified: 15 Apr 2026

    Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.

    Published: 25 Dec 2025
    7.4
    High

    CVE-2025-15091

    Last Modified: 31 Dec 2025

    A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 25 Dec 2025
    5.3
    Medium

    CVE-2025-14913

    Last Modified: 22 Apr 2026

    The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect authorization check on the 'media_delete_action' function in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to delete arbitrary attachments.

    Published: 25 Dec 2025
    7.4
    High

    CVE-2025-15090

    Last Modified: 31 Dec 2025

    A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

    Published: 25 Dec 2025
    7.4
    High

    CVE-2025-15089

    Last Modified: 31 Dec 2025

    A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

    Published: 25 Dec 2025
    2.1
    Low

    CVE-2025-15088

    Last Modified: 15 Apr 2026

    A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation of the argument keyWord results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    2.1
    Low

    CVE-2025-15087

    Last Modified: 26 Feb 2026

    A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    2.1
    Low

    CVE-2025-15086

    Last Modified: 31 Dec 2025

    A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    6.4
    Medium

    CVE-2025-68936

    Last Modified: 2 Jan 2026

    ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

    Published: 25 Dec 2025
    6.4
    Medium

    CVE-2025-68935

    Last Modified: 2 Jan 2026

    ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

    Published: 25 Dec 2025
    2.1
    Low

    CVE-2025-15085

    Last Modified: 31 Dec 2025

    A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    1.3
    Low

    CVE-2025-15084

    Last Modified: 31 Dec 2025

    A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java of the component Order Payment Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    0.3
    Low

    CVE-2025-15083

    Last Modified: 20 Jan 2026

    A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test interface with improper access control. The physical device can be targeted for the attack. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15082

    Last Modified: 20 Jan 2026

    A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information disclosure. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    2.1
    Low

    CVE-2025-15081

    Last Modified: 15 Apr 2026

    A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the argument ddns_name leads to command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Dec 2025
    7.6
    High

    CVE-2025-2307

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS). This issue affects Aidango: before 2.144.4.

    Published: 25 Dec 2025
    7.6
    High

    CVE-2025-2406

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS). This issue affects Trizbi: before 2.144.4.

    Published: 25 Dec 2025
    7.6
    High

    CVE-2025-2405

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS). This issue affects Titarus: before 2.144.4.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15078

    Last Modified: 30 Dec 2025

    A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /list_report.php. The manipulation of the argument sy results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15077

    Last Modified: 30 Dec 2025

    A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /form137.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15076

    Last Modified: 24 Feb 2026

    A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15075

    Last Modified: 30 Dec 2025

    A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.

    Published: 25 Dec 2025
    5.5
    Medium

    CVE-2025-15074

    Last Modified: 24 Feb 2026

    A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-66443

    Last Modified: 5 Jan 2026

    Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

    Published: 25 Dec 2025
    8.2
    High

    CVE-2025-59683

    Last Modified: 5 Jan 2026

    Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-66377

    Last Modified: 5 Jan 2026

    Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-32095

    Last Modified: 5 Jan 2026

    Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-32096

    Last Modified: 5 Jan 2026

    Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-48704

    Last Modified: 5 Jan 2026

    Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

    Published: 25 Dec 2025
    5.9
    Medium

    CVE-2025-66378

    Last Modified: 5 Jan 2026

    Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

    Published: 25 Dec 2025
    7.5
    High

    CVE-2025-66379

    Last Modified: 5 Jan 2026

    Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

    Published: 25 Dec 2025