CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-34408

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Added value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of existing markup and inject arbitrary script. A remote attacker can supply a crafted payload that closes an existing HTML list element, inserts attacker-controlled JavaScript, and comments out remaining code, leading to script execution in a victim’s browser when the victim visits a malicious link. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34398

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesBcc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable var sAddrBcc. By supplying a crafted payload that terminates the existing LoadCurAddresses() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34399

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable var sAddrCc. By supplying a crafted payload that terminates the existing LoadCurAddresses() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34400

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying a crafted payload that terminates the existing JavaScript function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34409

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of existing markup and inject arbitrary script. A remote attacker can supply a crafted payload that closes an existing HTML list element, inserts attacker-controlled JavaScript, and comments out remaining code, leading to script execution in a victim’s browser when the victim visits a malicious link. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34401

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var BCCFieldProvided. By supplying a crafted payload that terminates the existing LoadCurAddresses() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser during normal email composition. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34402

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var CCFieldProvided. By supplying a crafted payload that terminates the existing LoadCurAddresses() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34403

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var fieldTo. By supplying a crafted payload that terminates the existing Finish() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34406

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying a crafted payload that terminates an existing JavaScript function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim opens a malicious link. Successful exploitation can redirect victims to malicious sites, steal cookies not protected by HttpOnly, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34404

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The InstanceScope value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var gInstanceScope. By supplying a crafted payload that terminates the existing PageLoad() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34397

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter of /Mobile/Compose.aspx. The Message value is not properly sanitized when processed via a GET request and is reflected into a JavaScript context in the response. By supplying a crafted payload that terminates the existing script block/function, injects attacker-controlled JavaScript, and comments out the remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim opens the crafted reply URL. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-34407

    Last Modified: 5 Mar 2026

    MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter of /Mondo/lang/sys/Forms/Statistics.aspx. The theme value is insufficiently sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of an existing iframe context and inject arbitrary script. A remote attacker can supply a crafted payload that closes the iframe tag, inserts attacker-controlled JavaScript, and comments out remaining code, leading to script execution in a victim’s browser when the victim visits a malicious link. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62221

    Last Modified: 20 Apr 2026

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-54100

    Last Modified: 20 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-64680

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-64679

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-64678

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-64672

    Last Modified: 20 Apr 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 9 Dec 2025
    8.4
    High

    CVE-2025-64671

    Last Modified: 20 Apr 2026

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-64661

    Last Modified: 20 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-62565

    Last Modified: 20 Apr 2026

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.1
    High

    CVE-2025-62570

    Last Modified: 20 Apr 2026

    Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

    Published: 9 Dec 2025
    7
    High

    CVE-2025-62569

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-62567

    Last Modified: 20 Apr 2026

    Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62560

    Last Modified: 20 Apr 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62559

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62558

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    8.4
    High

    CVE-2025-62557

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62556

    Last Modified: 20 Apr 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7
    High

    CVE-2025-62555

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    8.4
    High

    CVE-2025-62554

    Last Modified: 22 May 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62553

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62552

    Last Modified: 20 Apr 2026

    Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-62550

    Last Modified: 20 Apr 2026

    Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62474

    Last Modified: 20 Apr 2026

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    5.5
    Medium

    CVE-2025-62468

    Last Modified: 20 Apr 2026

    Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62467

    Last Modified: 20 Apr 2026

    Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-55233

    Last Modified: 20 Apr 2026

    Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-62465

    Last Modified: 20 Apr 2026

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62464

    Last Modified: 20 Apr 2026

    Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-62463

    Last Modified: 20 Apr 2026

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62462

    Last Modified: 20 Apr 2026

    Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62461

    Last Modified: 20 Apr 2026

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62455

    Last Modified: 20 Apr 2026

    Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-59517

    Last Modified: 20 Apr 2026

    Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-59516

    Last Modified: 20 Apr 2026

    Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-64673

    Last Modified: 20 Apr 2026

    Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-64670

    Last Modified: 20 Apr 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

    Published: 9 Dec 2025
    7.5
    High

    CVE-2025-64666

    Last Modified: 15 Jun 2026

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-64667

    Last Modified: 15 Jun 2026

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Dec 2025