CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2025-49360

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology militarology allows PHP Local File Inclusion.This issue affects Militarology: from n/a through <= 1.0.15.

    Published: 18 Dec 2025
    8.1
    High

    CVE-2025-49359

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ShieldGroup shieldgroup allows PHP Local File Inclusion.This issue affects ShieldGroup: from n/a through <= 2.13.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-49041

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Get Cash: from n/a through <= 3.2.3.

    Published: 18 Dec 2025
    8.5
    High

    CVE-2025-14314

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit popup-builder-block allows Blind SQL Injection.This issue affects PopupKit: from n/a through <= 2.1.5.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-10019

    Last Modified: 24 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60.

    Published: 18 Dec 2025
    4.3
    Medium

    CVE-2025-13498

    Last Modified: 21 Apr 2026

    The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve passwords and access control settings for protected media attachments, which can then be used to bypass the intended media protection and download restricted files.

    Published: 18 Dec 2025
    6.4
    Medium

    CVE-2025-12976

    Last Modified: 22 Apr 2026

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2025
    8.6
    High

    CVE-2025-68459

    Last Modified: 15 Apr 2026

    RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. An arbitrary OS command may be executed on the product by an attacker who logs in to the CLI service.

    Published: 18 Dec 2025
    4.9
    Medium

    CVE-2025-68463

    Last Modified: 8 May 2026

    Bio.Entrez in Biopython through 186 allows doctype XXE.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47387

    Last Modified: 28 Jan 2026

    Memory Corruption when processing IOCTLs for JPEG data without verification.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47382

    Last Modified: 28 Jan 2026

    Memory corruption while loading an invalid firmware in boot loader.

    Published: 18 Dec 2025
    9
    Critical

    CVE-2025-47372

    Last Modified: 23 Dec 2025

    Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47350

    Last Modified: 23 Dec 2025

    Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-47325

    Last Modified: 23 Dec 2025

    Information disclosure while processing system calls with invalid parameters.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47323

    Last Modified: 28 Jan 2026

    Memory corruption while routing GPR packets between user and root when handling large data packet.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47322

    Last Modified: 28 Jan 2026

    Memory corruption while handling IOCTL calls to set mode.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47321

    Last Modified: 27 Jan 2026

    Memory corruption while copying packets received from unix clients.

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-47320

    Last Modified: 10 Feb 2026

    Memory corruption while processing MFC channel configuration during music playback.

    Published: 18 Dec 2025
    6.7
    Medium

    CVE-2025-47319

    Last Modified: 28 Jan 2026

    Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

    Published: 18 Dec 2025
    7.8
    High

    CVE-2025-27063

    Last Modified: 28 Jan 2026

    Memory corruption during video playback when video session open fails with time out error.

    Published: 18 Dec 2025
    3.2
    Low

    CVE-2025-68462

    Last Modified: 15 Apr 2026

    Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.

    Published: 18 Dec 2025
    7.2
    High

    CVE-2025-68461

    Last Modified: 26 Feb 2026

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

    Published: 18 Dec 2025
    7.2
    High

    CVE-2025-68460

    Last Modified: 2 Jan 2026

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

    Published: 18 Dec 2025
    6.4
    Medium

    CVE-2025-12885

    Last Modified: 21 Apr 2026

    The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2025
    2.1
    Low

    CVE-2025-14856

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

    Published: 18 Dec 2025
    1.9
    Low

    CVE-2025-14841

    Last Modified: 15 Apr 2026

    A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null pointer dereference. The attack requires local access. Upgrading to version 3.7.0 is sufficient to resolve this issue. Patch name: ffb1a4a37d2c876e3feeb31df4930f2aed7fa030. You should upgrade the affected component.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-63391

    Last Modified: 29 Jun 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65567

    Last Modified: 7 Jan 2026

    A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment Request with a CreatePDR that contains a malformed Flow-Description is not robustly validated. The Flow-Description parser (parseFlowDesc) can read beyond the bounds of the provided buffer, causing a panic and terminating the UPF process. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65565

    Last Modified: 7 Jan 2026

    A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Request that is missing the mandatory F-SEID (CPF-SEID) Information Element is not properly validated. The session establishment handler calls IE.FSEID() on a nil pointer, which triggers a panic and terminates the UPF process. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65563

    Last Modified: 7 Jan 2026

    A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association setup handler dereferences a nil pointer instead of validating the message, causing a panic and terminating the UPF process. An attacker who can send PFCP Association Setup Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-63951

    Last Modified: 31 Dec 2025

    An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, causing the application to process them and leading to errors or a denial of service.

    Published: 18 Dec 2025
    5.4
    Medium

    CVE-2025-63947

    Last Modified: 6 Jan 2026

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-63389

    Last Modified: 22 Jan 2026

    A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-63387

    Last Modified: 22 Jan 2026

    Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.

    Published: 18 Dec 2025
    6.1
    Medium

    CVE-2025-67163

    Last Modified: 31 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65568

    Last Modified: 7 Jan 2026

    A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that includes a CreateFAR with an empty or truncated IPv4 address field is not properly validated. During parsing, parseFAR() calls ip2int(), which performs an out-of-bounds read on the IPv4 address buffer and triggers an index-out-of-range panic. An attacker who can send PFCP Session Establishment Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65566

    Last Modified: 6 Jan 2026

    A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Session Report Response that is missing the mandatory Cause Information Element, the session report handler dereferences a nil pointer instead of rejecting the malformed message. This triggers a panic and terminates the UPF process. An attacker who can send PFCP Session Report Response messages to the UPF's N4/PFCP endpoint can exploit this flaw to repeatedly crash the UPF and disrupt user-plane services.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65564

    Last Modified: 7 Jan 2026

    A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler dereferences a nil pointer via IE.RecoveryTimeStamp() instead of validating the message. This results in a panic and terminates the UPF process. An attacker who can send PFCP Association Setup Request messages to the UPF's N4/PFCP endpoint can exploit this issue to repeatedly crash the UPF and disrupt user-plane services.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65562

    Last Modified: 7 Jan 2026

    The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode.Sess() when a uint64 SEID is converted to int and used in index arithmetic. This leads to a negative index into n.sess and a Go runtime panic, resulting in a denial of service (UPF crash). The issue has been reproduced on free5GC v4.1.0 with crashes observed in the session lookup/deletion path in internal/pfcp/node.go; other versions may also be affected. No authentication is required.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-63950

    Last Modified: 31 Dec 2025

    An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through commit b1c58a7d1dc664b38deb486ca290779621342c0b (2023-02-28). The 'obj' parameter receives base64-encoded data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, leading to a denial of service.

    Published: 18 Dec 2025
    6.1
    Medium

    CVE-2025-63949

    Last Modified: 31 Dec 2025

    A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

    Published: 18 Dec 2025
    5.4
    Medium

    CVE-2025-63948

    Last Modified: 31 Dec 2025

    A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-63757

    Last Modified: 30 Dec 2025

    Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

    Published: 18 Dec 2025
    9.1
    Critical

    CVE-2025-63388

    Last Modified: 28 Jan 2026

    A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65559

    Last Modified: 6 Jan 2026

    An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI?F-TEID has CH=1 and the F-TEID address-family flag(s) (IPv4/IPv6) do not match the GTP-U resource family configured for the selected DNN (Network Instance), resulting in a denial of service.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-56157

    Last Modified: 29 Jan 2026

    Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

    Published: 18 Dec 2025
    7.5
    High

    CVE-2025-65561

    Last Modified: 7 Jan 2026

    An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

    Published: 18 Dec 2025
    Unknown

    CVE-2025-68325

    Last Modified: 15 Apr 2026

    In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop In cake_drop(), qdisc_tree_reduce_backlog() is used to update the qlen and backlog of the qdisc hierarchy. Its caller, cake_enqueue(), assumes that the parent qdisc will enqueue the current packet. However, this assumption breaks when cake_enqueue() returns NET_XMIT_CN: the parent qdisc stops enqueuing current packet, leaving the tree qlen/backlog accounting inconsistent. This mismatch can lead to a NULL dereference (e.g., when the parent Qdisc is qfq_qdisc). This patch computes the qlen/backlog delta in a more robust way by observing the difference before and after the series of cake_drop() calls, and then compensates the qdisc tree accounting if cake_enqueue() returns NET_XMIT_CN. To ensure correct compensation when ACK thinning is enabled, a new variable is introduced to keep qlen unchanged.

    Published: 18 Dec 2025
    9.1
    Critical

    CVE-2025-63386

    Last Modified: 11 Feb 2026

    A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-63390

    Last Modified: 22 Jan 2026

    An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. Exposed data includes: workspace identifiers (id, name, slug), AI model configurations (chatProvider, chatModel, agentProvider), system prompts (openAiPrompt), operational parameters (temperature, history length, similarity thresholds), vector search settings, chat modes, and timestamps.

    Published: 18 Dec 2025