CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2025-67845

    Last Modified: 2 Jan 2026

    A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.

    Published: 19 Dec 2025
    9.8
    Critical

    CVE-2025-63665

    Last Modified: 5 Jan 2026

    An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.

    Published: 19 Dec 2025
    7.6
    High

    CVE-2025-67442

    Last Modified: 2 Jan 2026

    EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.

    Published: 19 Dec 2025
    2
    Low

    CVE-2025-14898

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

    Published: 18 Dec 2025
    2
    Low

    CVE-2025-14897

    Last Modified: 24 Feb 2026

    A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

    Published: 18 Dec 2025
    8.3
    High

    CVE-2025-64675

    Last Modified: 20 Apr 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.

    Published: 18 Dec 2025
    9.1
    Critical

    CVE-2025-68398

    Last Modified: 6 Feb 2026

    Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

    Published: 18 Dec 2025
    7.7
    High

    CVE-2025-68279

    Last Modified: 2 Jan 2026

    Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

    Published: 18 Dec 2025
    4.3
    Medium

    CVE-2025-68422

    Last Modified: 23 Dec 2025

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries.

    Published: 18 Dec 2025
    4.3
    Medium

    CVE-2025-68386

    Last Modified: 23 Dec 2025

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request.

    Published: 18 Dec 2025
    4.9
    Medium

    CVE-2025-68390

    Last Modified: 23 Dec 2025

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-68389

    Last Modified: 23 Dec 2025

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.

    Published: 18 Dec 2025
    6.1
    Medium

    CVE-2025-68387

    Last Modified: 23 Dec 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.

    Published: 18 Dec 2025
    7.2
    High

    CVE-2025-68385

    Last Modified: 23 Dec 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-68384

    Last Modified: 23 Dec 2025

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

    Published: 18 Dec 2025
    8.2
    High

    CVE-2025-64677

    Last Modified: 20 Apr 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.

    Published: 18 Dec 2025
    7.2
    High

    CVE-2025-64676

    Last Modified: 20 Apr 2026

    '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

    Published: 18 Dec 2025
    10
    Critical

    CVE-2025-65037

    Last Modified: 20 Apr 2026

    Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

    Published: 18 Dec 2025
    10
    Critical

    CVE-2025-65041

    Last Modified: 20 Apr 2026

    Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

    Published: 18 Dec 2025
    9.9
    Critical

    CVE-2025-64663

    Last Modified: 20 Apr 2026

    Custom Question Answering Elevation of Privilege Vulnerability

    Published: 18 Dec 2025
    3.1
    Low

    CVE-2025-65046

    Last Modified: 20 Apr 2026

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-68383

    Last Modified: 23 Dec 2025

    Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2025-13427

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents, gaining access to the agents' knowledge and the ability to trigger their intents, by manipulating initialization parameters or crafting specific API requests. All versions after August 20th, 2025 have been updated to protect from this vulnerability. No user action is required for this.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-68382

    Last Modified: 23 Dec 2025

    Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-68381

    Last Modified: 23 Dec 2025

    Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-68388

    Last Modified: 23 Dec 2025

    Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2025-34452

    Last Modified: 15 Apr 2026

    Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the server filesystem. The issue exists in the subtitle download functionality, where user-controlled parameters are used to fetch remote content and construct file paths without proper validation. By supplying a crafted subtitle download URL and a path traversal sequence in the file name, an attacker can write files to arbitrary locations on the server, potentially leading to remote code execution.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2025-34451

    Last Modified: 23 Mar 2026

    rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflow vulnerability in the function proxy_from_string() located in src/libproxychains.c. When parsing crafted proxy configuration entries containing overly long username or password fields, the application may write beyond the bounds of fixed-size stack buffers, leading to memory corruption or crashes. This vulnerability may allow denial of service and, under certain conditions, could be leveraged for further exploitation depending on the execution environment and applied mitigations.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2025-34450

    Last Modified: 23 Mar 2026

    merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vulnerability in the function parse_rfraw() located in src/rfraw.c. When processing crafted or excessively large raw RF input data, the application may write beyond the bounds of a stack buffer, resulting in memory corruption or a crash. This vulnerability can be exploited to cause a denial of service and, under certain conditions, may be leveraged for further exploitation depending on the execution environment and available mitigations.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2025-34449

    Last Modified: 23 Mar 2026

    Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds reads, which may result in memory corruption or a denial-of-service condition. This vulnerability may allow further exploitation on the host system.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-53710

    Last Modified: 15 Apr 2026

    Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands locally.

    Published: 18 Dec 2025
    6.3
    Medium

    CVE-2025-68161

    Last Modified: 20 Apr 2026

    The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true. This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions: * The attacker is able to intercept or redirect network traffic between the client and the log receiver. * The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured). Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue. As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-67653

    Last Modified: 31 Dec 2025

    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

    Published: 18 Dec 2025
    7.7
    High

    CVE-2025-62004

    Last Modified: 15 Jan 2026

    BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP MFA. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions mayy also be affected. BullWall plans to improve detection method documentation.

    Published: 18 Dec 2025
    7.7
    High

    CVE-2025-62003

    Last Modified: 15 Jan 2026

    BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-46268

    Last Modified: 31 Dec 2025

    Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-14848

    Last Modified: 31 Dec 2025

    Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-62002

    Last Modified: 15 Jan 2026

    BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes. The number of files to trigger detection can be configured by the user. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2025-14849

    Last Modified: 31 Dec 2025

    Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2025-62001

    Last Modified: 15 Jan 2026

    BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed in 4.6.1.14 and 5.0.0.42, which remove hardcoded exclusion behavior and exposes exclusion handling as configurable settings.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2025-62000

    Last Modified: 15 Jan 2026

    BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header bytes. An authenticated attacker could encrypt files, preserving the first four bytes and preventing this particular method from triggering. The affected product implements additional integrity-based detection mechanisms capable of identifying file corruption or encryption for some common file extensions independent of header bytes. As a result, this vulnerability does not represent a complete bypass of ransomware detection, but a limitation of one detection method when evaluated independently. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected. BullWall plans to improve detection method documentation.

    Published: 18 Dec 2025
    7.2
    High

    CVE-2025-14850

    Last Modified: 31 Dec 2025

    Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

    Published: 18 Dec 2025
    7.3
    High

    CVE-2025-13911

    Last Modified: 28 Aug 2026

    Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.

    Published: 18 Dec 2025
    2.1
    Low

    CVE-2025-14889

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 18 Dec 2025
    8.4
    High

    CVE-2023-53940

    Last Modified: 15 Apr 2026

    Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file is opened.

    Published: 18 Dec 2025
    8.5
    High

    CVE-2023-53937

    Last Modified: 7 Apr 2026

    Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2024-58323

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2024-58322

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2024-58321

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2024-58320

    Last Modified: 24 Dec 2025

    An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details.

    Published: 18 Dec 2025