CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-56114

    Last Modified: 7 Jan 2026

    OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56130

    Last Modified: 31 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to the module_update in file /usr/local/lua/dev_config/ace_sw.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56079

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56120

    Last Modified: 23 Dec 2025

    OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-65471

    Last Modified: 18 Dec 2025

    An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56084

    Last Modified: 11 Feb 2026

    OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-66429

    Last Modified: 15 Dec 2025

    An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

    Published: 11 Dec 2025
    9.8
    Critical

    CVE-2025-65474

    Last Modified: 19 Dec 2025

    An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format.

    Published: 11 Dec 2025
    7.5
    High

    CVE-2025-59802

    Last Modified: 18 Dec 2025

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.

    Published: 11 Dec 2025
    5.3
    Medium

    CVE-2025-59803

    Last Modified: 15 Dec 2025

    Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a signer reviews the document, the content appears normal. However, once the signature is applied, the triggers modify content on other pages or optional content layers without explicit warning. This can cause the signed PDF to differ from what the signer saw, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56122

    Last Modified: 23 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56087

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump.lua.

    Published: 11 Dec 2025
    6.1
    Medium

    CVE-2025-55816

    Last Modified: 15 Dec 2025

    HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56091

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025
    3.3
    Low

    CVE-2025-55307

    Last Modified: 6 Jan 2026

    An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a crafted JavaScript call to search.query() with a crafted cDIPath parameter (e.g., "/") may cause an out-of-bounds read in internal path-parsing logic, potentially leading to information disclosure or memory corruption.

    Published: 11 Dec 2025
    7.8
    High

    CVE-2025-55313

    Last Modified: 18 Dec 2025

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation failures after assigning an extremely large value to a form field's charLimit property via JavaScript. This can result in memory corruption and may allow an attacker to execute arbitrary code by persuading a user to open a malicious file.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-66918

    Last Modified: 23 Dec 2025

    edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56129

    Last Modified: 15 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56111

    Last Modified: 7 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56118

    Last Modified: 23 Dec 2025

    OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56107

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56099

    Last Modified: 11 Feb 2026

    OS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56093

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56089

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56095

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56077

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56083

    Last Modified: 11 Feb 2026

    OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge.lua.

    Published: 11 Dec 2025
    9.1
    Critical

    CVE-2025-65473

    Last Modified: 15 Dec 2025

    An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an uploaded file name.

    Published: 11 Dec 2025
    6.5
    Medium

    CVE-2025-55311

    Last Modified: 7 Jan 2026

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

    Published: 11 Dec 2025
    6.7
    Medium

    CVE-2025-55309

    Last Modified: 6 Jan 2026

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.

    Published: 11 Dec 2025
    7.8
    High

    CVE-2025-55312

    Last Modified: 18 Dec 2025

    An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56127

    Last Modified: 18 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56123

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56117

    Last Modified: 7 Jan 2026

    OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56113

    Last Modified: 11 Feb 2026

    OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56110

    Last Modified: 26 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_deal_update in file /usr/lib/lua/luci/controller/api/rcmsAPI.lua.

    Published: 11 Dec 2025
    7.8
    High

    CVE-2025-55314

    Last Modified: 18 Dec 2025

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56109

    Last Modified: 26 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56108

    Last Modified: 26 Jan 2026

    OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56097

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56102

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56101

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56085

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56086

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56096

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common.lua.

    Published: 11 Dec 2025
    7.3
    High

    CVE-2025-55310

    Last Modified: 18 Dec 2025

    An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other security impacts.

    Published: 11 Dec 2025
    6.7
    Medium

    CVE-2025-55308

    Last Modified: 6 Jan 2026

    An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56082

    Last Modified: 26 Dec 2025

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes in file /usr/lib/lua/luci/controller/admin/common.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56088

    Last Modified: 26 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service.lua.

    Published: 11 Dec 2025
    8.8
    High

    CVE-2025-56090

    Last Modified: 27 Jan 2026

    OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

    Published: 11 Dec 2025