CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-48536

    Last Modified: 26 Feb 2026

    In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    7.8
    High

    CVE-2025-48525

    Last Modified: 26 Feb 2026

    In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a companion device due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    7.8
    High

    CVE-2025-32329

    Last Modified: 26 Feb 2026

    In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    7.8
    High

    CVE-2025-32328

    Last Modified: 26 Feb 2026

    In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    6.7
    Medium

    CVE-2025-32319

    Last Modified: 26 Feb 2026

    In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    6.7
    Medium

    CVE-2025-22432

    Last Modified: 26 Feb 2026

    In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    7.8
    High

    CVE-2025-22420

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14256

    Last Modified: 9 Dec 2025

    A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14251

    Last Modified: 9 Dec 2025

    A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14250

    Last Modified: 10 Dec 2025

    A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

    Published: 8 Dec 2025
    Unknown

    CVE-2025-14271

    Last Modified: 8 Dec 2025

    This CVE ID has been withdrawn by its CVE Numbering Authority.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14249

    Last Modified: 10 Dec 2025

    A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school.php. The manipulation of the argument product_id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14248

    Last Modified: 9 Dec 2025

    A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

    Published: 8 Dec 2025
    Unknown

    CVE-2025-14268

    Last Modified: 17 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14247

    Last Modified: 9 Dec 2025

    A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14246

    Last Modified: 9 Dec 2025

    A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14245

    Last Modified: 11 Dec 2025

    A vulnerability has been found in IdeaCMS up to 1.8. This affects the function whereRaw of the file app/common/logic/index/Coupon.php. Such manipulation of the argument params leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2025
    8.3
    High

    CVE-2025-42620

    Last Modified: 15 Apr 2026

    In affected versions, vulnerability-lookup handled user-controlled content in comments and bundles in an unsafe way, which could lead to stored Cross-Site Scripting (XSS). On the backend, the related_vulnerabilities field of bundles accepted arbitrary strings without format validation or proper sanitization. On the frontend, comment and bundle descriptions were converted from Markdown to HTML and then injected directly into the DOM using string templates and innerHTML. This combination allowed an attacker who could create or edit comments or bundles to store crafted HTML/JavaScript payloads which would later be rendered and executed in the browser of any user visiting the affected profile page (user.html).  This issue affects Vulnerability-Lookup: before 2.18.0.

    Published: 8 Dec 2025
    7
    High

    CVE-2025-42616

    Last Modified: 15 Apr 2026

    Some endpoints in vulnerability-lookup that modified application state (e.g. changing database entries, user data, configurations, or other privileged actions) may have been accessible via HTTP GET requests without requiring a CSRF token. This flaw leaves the application vulnerable to Cross-Site Request Forgery (CSRF) attacks: an attacker who tricks a logged-in user into visiting a malicious website could cause the user’s browser to issue GET requests that perform unintended state-changing operations in the context of their authenticated session. Because the server would treat these GET requests as valid (since no CSRF protection or POST method enforcement was in place), the attacker could exploit this to escalate privileges, change settings, or carry out other unauthorized actions without needing the user’s explicit consent or awareness.  The fix ensures that all state-changing endpoints now require HTTP POST requests and include a valid CSRF token. This enforces that state changes cannot be triggered by arbitrary cross-site GET requests. This issue affects Vulnerability-Lookup: before 2.18.0.

    Published: 8 Dec 2025
    1.9
    Low

    CVE-2025-14244

    Last Modified: 24 Feb 2026

    A flaw has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of the file /Admin/Controller/CustomController.class.php of the component Menu Management Page. This manipulation of the argument Link causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 Dec 2025
    8.1
    High

    CVE-2025-42615

    Last Modified: 15 Apr 2026

    In affected versions, vulnerability-lookup did not track or limit failed One-Time Password (OTP) attempts during Two-Factor Authentication (2FA) verification. An attacker who already knew or guessed a valid username and password could submit an arbitrary number of OTP codes without causing the account to be locked or generating any specific alert for administrators. This lack of rate-limiting and lockout on OTP failures significantly lowers the cost of online brute-force attacks against 2FA codes and increases the risk of successful account takeover, especially if OTP entropy is reduced (e.g. short numeric codes, user reuse, or predictable tokens). Additionally, administrators had no direct visibility into accounts experiencing repeated 2FA failures, making targeted attacks harder to detect and investigate. The patch introduces a persistent failed_otp_attempts counter on user accounts, locks the user after 5 invalid OTP submissions, resets the counter on successful verification, and surfaces failed 2FA attempts in the admin user list. This enforces an account lockout policy for OTP brute-force attempts and improves monitoring capabilities for suspicious 2FA activity.This issue affects Vulnerability-Lookup: before 2.18.0.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14230

    Last Modified: 10 Dec 2025

    A vulnerability was detected in code-projects Daily Time Recording System 4.5.0. The impacted element is an unknown function of the file /admin/add_payroll.php. Performing manipulation of the argument detail_Id results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 8 Dec 2025
    2
    Low

    CVE-2025-14229

    Last Modified: 10 Dec 2025

    A security vulnerability has been detected in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the component SVC Report Export. Such manipulation leads to csv injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 8 Dec 2025
    2
    Low

    CVE-2025-14228

    Last Modified: 15 Apr 2026

    A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local Directory Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14227

    Last Modified: 21 Jan 2026

    A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown processing of the file /edit.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Dec 2025
    5.3
    Medium

    CVE-2025-14262

    Last Modified: 27 Feb 2026

    A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions. There is no workaround.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14226

    Last Modified: 10 Dec 2025

    A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Other parameters might be affected as well.

    Published: 8 Dec 2025
    8.4
    High

    CVE-2025-66461

    Last Modified: 15 Apr 2026

    FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.

    Published: 8 Dec 2025
    9.8
    Critical

    CVE-2025-27020

    Last Modified: 22 Dec 2025

    Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

    Published: 8 Dec 2025
    9.8
    Critical

    CVE-2025-27019

    Last Modified: 22 Dec 2025

    Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14225

    Last Modified: 11 Dec 2025

    A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 Dec 2025
    6.5
    Medium

    CVE-2025-26489

    Last Modified: 22 Dec 2025

    Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

    Published: 8 Dec 2025
    7.5
    High

    CVE-2025-26488

    Last Modified: 22 Dec 2025

    Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

    Published: 8 Dec 2025
    8.6
    High

    CVE-2025-26487

    Last Modified: 22 Dec 2025

    Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.

    Published: 8 Dec 2025
    8.7
    High

    CVE-2025-12956

    Last Modified: 12 Jan 2026

    A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 8 Dec 2025
    4.9
    Medium

    CVE-2025-66330

    Last Modified: 9 Dec 2025

    App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2025
    4
    Medium

    CVE-2025-66329

    Last Modified: 9 Jun 2026

    Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    2.1
    Low

    CVE-2025-14224

    Last Modified: 12 Dec 2025

    A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Dec 2025
    6.2
    Medium

    CVE-2025-66325

    Last Modified: 9 Dec 2025

    Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2025
    4.4
    Medium

    CVE-2025-58279

    Last Modified: 9 Dec 2025

    Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2025
    3.3
    Low

    CVE-2025-66334

    Last Modified: 9 Dec 2025

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    3.3
    Low

    CVE-2025-66333

    Last Modified: 9 Dec 2025

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    3.3
    Low

    CVE-2025-66332

    Last Modified: 9 Dec 2025

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    3.3
    Low

    CVE-2025-66331

    Last Modified: 9 Dec 2025

    Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    8.4
    High

    CVE-2025-66328

    Last Modified: 8 Dec 2025

    Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    7.1
    High

    CVE-2025-66327

    Last Modified: 8 Dec 2025

    Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2025
    6.7
    Medium

    CVE-2025-66326

    Last Modified: 9 Dec 2025

    Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    8.4
    High

    CVE-2025-66324

    Last Modified: 9 Dec 2025

    Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app data integrity.

    Published: 8 Dec 2025
    5.3
    Medium

    CVE-2025-66323

    Last Modified: 9 Dec 2025

    Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Dec 2025
    5.5
    Medium

    CVE-2025-14223

    Last Modified: 7 Jan 2026

    A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of the argument staff_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2025