CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2025-13155

    Last Modified: 15 Apr 2026

    An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges.

    Published: 10 Dec 2025
    8.5
    High

    CVE-2025-13152

    Last Modified: 15 Apr 2026

    A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

    Published: 10 Dec 2025
    8.5
    High

    CVE-2025-12046

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions.

    Published: 10 Dec 2025
    3.5
    Low

    CVE-2025-13127

    Last Modified: 4 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1.

    Published: 10 Dec 2025
    6.4
    Medium

    CVE-2025-14443

    Last Modified: 15 Apr 2026

    A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.

    Published: 10 Dec 2025
    8.7
    High

    CVE-2025-8110

    Last Modified: 26 Feb 2026

    Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

    Published: 10 Dec 2025
    6.5
    Medium

    CVE-2024-2105

    Last Modified: 15 Apr 2026

    An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

    Published: 10 Dec 2025
    8.8
    High

    CVE-2024-2104

    Last Modified: 15 Apr 2026

    Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-13184

    Last Modified: 19 Dec 2025

    Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.

    Published: 10 Dec 2025
    9.3
    Critical

    CVE-2025-13953

    Last Modified: 15 Apr 2026

    Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through a local WebSocket, but the web application does not properly validate the authenticity or origin of the data received, allowing an attacker with access to the local machine or internal network to impersonate the legitimate WebSocket and inject manipulated information. Exploiting this vulnerability could allow an attacker to authenticate as any user in the domain, without the need for valid credentials, compromising the confidentiality, integrity, and availability of the application and its data.

    Published: 10 Dec 2025
    8.3
    High

    CVE-2025-41358

    Last Modified: 15 Apr 2026

    Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/AdjuntarDocumentosPersonas'.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-41732

    Last Modified: 19 Dec 2025

    An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-41730

    Last Modified: 19 Dec 2025

    An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67689

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67690

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67691

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67692

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67693

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67694

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67687

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67688

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    Unknown

    CVE-2025-67686

    Last Modified: 11 Dec 2025

    Not used

    Published: 10 Dec 2025
    8.8
    High

    CVE-2025-7073

    Last Modified: 31 Mar 2026

    A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate privileges. The issue arises from bdservicehost.exe deleting files from a user-writable directory (C:\ProgramData\Atc\Feedback) without proper symbolic link validation, enabling arbitrary file deletion. This issue is chained with a file copy operation during network events and a filter driver bypass via DLL injection to achieve arbitrary file copy and code execution as elevated user.

    Published: 10 Dec 2025
    8.2
    High

    CVE-2025-66675

    Last Modified: 16 Dec 2025

    Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to  https://cve.org/CVERecord?id=CVE-2025-64775  - this CVE addresses missing affected version 6.7.4

    Published: 10 Dec 2025
    8.8
    High

    CVE-2025-14390

    Last Modified: 21 Apr 2026

    The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to missing or incorrect nonce validation on the video_merchant_add_video_file() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Dec 2025
    5.1
    Medium

    CVE-2025-66004

    Last Modified: 15 Apr 2026

    A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.

    Published: 10 Dec 2025
    7.1
    High

    CVE-2025-1161

    Last Modified: 6 Jun 2026

    Incorrect Use of Privileged APIs vulnerability in NomySoft Information Technology Training and Consulting Inc. Nomysem allows Privilege Escalation. This issue affects Nomysem: through May 2025.

    Published: 10 Dec 2025
    6.3
    Medium

    CVE-2025-9315

    Last Modified: 15 Apr 2026

    An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determined Object Attributes, has been identified in the MXsecurity Series. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted JSON payload to the device's registration endpoint /api/v1/devices/register, allowing the attacker to register unauthorized devices without authentication. Although exploiting this vulnerability has limited modification of data, there is no impact to the confidentiality and availability of the affected device, as well as no loss of confidentiality, integrity, and availability within any subsequent systems.

    Published: 10 Dec 2025
    9.3
    Critical

    CVE-2025-13955

    Last Modified: 28 May 2026

    Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identifiers

    Published: 10 Dec 2025
    9.3
    Critical

    CVE-2025-13954

    Last Modified: 28 May 2026

    Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI

    Published: 10 Dec 2025
    8.7
    High

    CVE-2025-12952

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. This allows the attacker to escalate their privileges from agent-level to project-level, granting them unauthorized access to manage resources in services associated with the project, leading to unexpected costs and resource depletion for the producer project. A fix was applied on the server side to protect from this vulnerability in February 2025. No customer action is required.

    Published: 10 Dec 2025
    8.7
    High

    CVE-2025-9571

    Last Modified: 15 Apr 2026

    A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure. The following CDAP versions include the necessary update to protect against this vulnerability: * 6.10.6+ * 6.11.1+  Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases .

    Published: 10 Dec 2025
    7.1
    High

    CVE-2025-13073

    Last Modified: 15 Apr 2026

    The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 10 Dec 2025
    7.1
    High

    CVE-2025-13072

    Last Modified: 15 Apr 2026

    The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 10 Dec 2025
    7.5
    High

    CVE-2025-13339

    Last Modified: 22 Apr 2026

    The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 10 Dec 2025
    5.3
    Medium

    CVE-2025-9056

    Last Modified: 2 Jan 2026

    Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

    Published: 10 Dec 2025
    4.9
    Medium

    CVE-2025-13677

    Last Modified: 21 Apr 2026

    The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient path validation in the `simple_download_counter_parse_path()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which may contain sensitive information such as database credentials (wp-config.php) or system files. Please note that the vendor opted to continue to allow remote file downloads from arbitrary locations on the server, however, has disabled this functionality on multi-sites and provided a warning to site owners in the readme.txt when they install the plugin. While not an optimal patch, we have considered this sufficient and recommend users proceed to use the plugin with caution.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-13613

    Last Modified: 22 Apr 2026

    The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'eltdf_membership_check_facebook_user' and the 'eltdf_membership_login_user_from_social_network' function. This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user's email.

    Published: 10 Dec 2025
    8.1
    High

    CVE-2025-67507

    Last Modified: 4 Mar 2026

    Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. This issue is fixed in version 4.3.1.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-67506

    Last Modified: 17 Mar 2026

    PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by uploading payload to os.path.join(tmpdir, file.filename) without normalizing the filename. An attacker can submit a crafted filename containing ../ sequences to write arbitrary files anywhere the service account has permission, enabling remote file overwrite or planting malicious code. This issue is fixed in version 0.1.0-beta.

    Published: 10 Dec 2025
    5.3
    Medium

    CVE-2025-67485

    Last Modified: 9 Mar 2026

    mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at the time of publication.

    Published: 10 Dec 2025
    6.5
    Medium

    CVE-2025-52493

    Last Modified: 2 Jan 2026

    PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "password" to "text" using browser developer tools. This vulnerability is exploitable by administrative users who have access to the configuration page.

    Published: 10 Dec 2025
    9.8
    Critical

    CVE-2025-65602

    Last Modified: 18 Dec 2025

    A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

    Published: 10 Dec 2025
    6.5
    Medium

    CVE-2025-65814

    Last Modified: 17 Dec 2025

    A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.

    Published: 10 Dec 2025
    6.5
    Medium

    CVE-2025-65803

    Last Modified: 17 Dec 2025

    An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted PSD file.

    Published: 10 Dec 2025
    7.4
    High

    CVE-2025-65290

    Last Modified: 17 Dec 2025

    Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.

    Published: 10 Dec 2025
    7.5
    High

    CVE-2025-56430

    Last Modified: 18 Dec 2025

    Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.

    Published: 10 Dec 2025
    9.1
    Critical

    CVE-2025-65792

    Last Modified: 17 Dec 2025

    DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

    Published: 10 Dec 2025
    8.8
    High

    CVE-2025-65824

    Last Modified: 21 Jan 2026

    An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the attacker's code. As the device does not perform checks on upgrades, this results in Remote Code Execution (RCE) and the victim losing complete access to the Meatmeet.

    Published: 10 Dec 2025
    6.8
    Medium

    CVE-2025-65822

    Last Modified: 21 Jan 2026

    The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be executed upon running. As a result, the victim will lose access to the functionality of their device and the attack may gain unauthorized access to the victim's Wi-Fi network by re-connecting to the SSID defined in the NVS partition of the device.

    Published: 10 Dec 2025