CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2025-13937

    Last Modified: 10 Aug 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.

    Published: 4 Dec 2025
    4.8
    Medium

    CVE-2025-13936

    Last Modified: 10 Aug 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.

    Published: 4 Dec 2025
    8.6
    High

    CVE-2025-12196

    Last Modified: 10 Aug 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2025-53704

    Last Modified: 15 Apr 2026

    The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

    Published: 4 Dec 2025
    8.6
    High

    CVE-2025-12195

    Last Modified: 10 Aug 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.

    Published: 4 Dec 2025
    8.6
    High

    CVE-2025-12026

    Last Modified: 10 Aug 2026

    An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.

    Published: 4 Dec 2025
    7.4
    High

    CVE-2025-10285

    Last Modified: 15 Apr 2026

    The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.

    Published: 4 Dec 2025
    8.3
    High

    CVE-2025-13932

    Last Modified: 15 Apr 2026

    The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticated user can access detailed data of any plant by altering the plant_id in the request.

    Published: 4 Dec 2025
    7.4
    High

    CVE-2025-66238

    Last Modified: 15 Apr 2026

    DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

    Published: 4 Dec 2025
    Unknown

    CVE-2025-14066

    Last Modified: 12 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 4 Dec 2025
    8.4
    High

    CVE-2025-66237

    Last Modified: 15 Apr 2026

    DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

    Published: 4 Dec 2025
    1.8
    Low

    CVE-2025-66479

    Last Modified: 15 Apr 2026

    Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2025-65959

    Last Modified: 10 Dec 2025

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing them to execute arbitrary JavaScript code and steal session tokens when a victim downloads the note as PDF. This vulnerability can be exploited by any authenticated user, and unauthenticated external attackers can steal session tokens from users (both admin and regular users) by sharing specially crafted markdown files. This vulnerability is fixed in 0.6.37.

    Published: 4 Dec 2025
    8.9
    High

    CVE-2025-66576

    Last Modified: 14 Jul 2026

    Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

    Published: 4 Dec 2025
    8.5
    High

    CVE-2025-66575

    Last Modified: 30 Dec 2025

    VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem.

    Published: 4 Dec 2025
    5.3
    Medium

    CVE-2025-66574

    Last Modified: 7 Apr 2026

    TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.

    Published: 4 Dec 2025
    6.9
    Medium

    CVE-2025-66573

    Last Modified: 14 Jul 2026

    Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that exposes sensitive information such as the session key, server version, product details, and display name. Unauthorized users can extract live session information by accessing this endpoint without authentication.

    Published: 4 Dec 2025
    6.9
    Medium

    CVE-2025-66572

    Last Modified: 26 May 2026

    Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute arbitrary code in the victim's browser context when they visit a crafted URL.

    Published: 4 Dec 2025
    9.3
    Critical

    CVE-2025-66571

    Last Modified: 28 Jul 2026

    UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where the profile_id POST parameter is passed to PHP unserialize() without proper handling, allowing remote, unauthenticated attackers to inject arbitrary PHP objects and potentially write and execute arbitrary PHP code.

    Published: 4 Dec 2025
    8.8
    High

    CVE-2025-66555

    Last Modified: 15 Apr 2026

    AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.

    Published: 4 Dec 2025
    8.5
    High

    CVE-2024-58278

    Last Modified: 15 Apr 2026

    perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2024-58277

    Last Modified: 15 Apr 2026

    R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2024-58276

    Last Modified: 14 Aug 2026

    Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2024-58275

    Last Modified: 15 Apr 2026

    Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.

    Published: 4 Dec 2025
    5.3
    Medium

    CVE-2023-53735

    Last Modified: 15 Apr 2026

    WEBIGniter 28.7.23 contains a cross-site scripting vulnerability in the user creation process that allows unauthenticated attackers to execute malicious JavaScript code, enabling potential XSS attacks.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2023-53734

    Last Modified: 15 Apr 2026

    dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.

    Published: 4 Dec 2025
    8.6
    High

    CVE-2025-27935

    Last Modified: 15 Apr 2026

    The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.

    Published: 4 Dec 2025
    8.8
    High

    CVE-2025-13543

    Last Modified: 22 Apr 2026

    The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1.12.5. This makes it possible for authenticated attackers, with subscriber-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 4 Dec 2025
    2.2
    Low

    CVE-2025-12997

    Last Modified: 22 Dec 2025

    Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.

    Published: 4 Dec 2025
    4.1
    Medium

    CVE-2025-12996

    Last Modified: 22 Dec 2025

    Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

    Published: 4 Dec 2025
    8.1
    High

    CVE-2025-12995

    Last Modified: 22 Dec 2025

    Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

    Published: 4 Dec 2025
    5.3
    Medium

    CVE-2025-12994

    Last Modified: 22 Dec 2025

    Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.

    Published: 4 Dec 2025
    8.5
    High

    CVE-2025-65958

    Last Modified: 10 Dec 2025

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to access cloud metadata endpoints (AWS/GCP/Azure), scan internal networks, access internal services behind firewalls, and exfiltrate sensitive information. No special permissions beyond basic authentication are required. This vulnerability is fixed in 0.6.37.

    Published: 4 Dec 2025
    8.7
    High

    CVE-2025-12097

    Last Modified: 15 Apr 2026

    There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure.  Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files.  This vulnerability existed in the NI System Web Server 2012 and prior versions.  It was fixed in 2013.

    Published: 4 Dec 2025
    7.5
    High

    CVE-2025-65945

    Last Modified: 9 Mar 2026

    auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verification. This issue has been patched in versions 3.2.3 and 4.0.1.

    Published: 4 Dec 2025
    2.1
    Low

    CVE-2025-14016

    Last Modified: 15 Dec 2025

    A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    7.4
    High

    CVE-2025-14015

    Last Modified: 23 Dec 2025

    A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    5.1
    Medium

    CVE-2025-13488

    Last Modified: 15 Apr 2026

    Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context.

    Published: 4 Dec 2025
    1.9
    Low

    CVE-2025-14013

    Last Modified: 24 Feb 2026

    A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/admins/Comment/addcomment.html of the component Comment Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    8.4
    High

    CVE-2025-9127

    Last Modified: 3 Feb 2026

    A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

    Published: 4 Dec 2025
    2
    Low

    CVE-2025-14012

    Last Modified: 24 Feb 2026

    A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    2
    Low

    CVE-2025-14011

    Last Modified: 24 Feb 2026

    A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the component Add Display Name Field. Performing a manipulation of the argument aid/tid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    8.4
    High

    CVE-2025-66516

    Last Modified: 26 Feb 2026

    Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways. First, while the entrypoint for the vulnerability was the tika-parser-pdf-module as reported in CVE-2025-54988, the vulnerability and its fix were in tika-core. Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable. Second, the original report failed to mention that in the 1.x Tika releases, the PDFParser was in the "org.apache.tika:tika-parsers" module.

    Published: 4 Dec 2025
    5.6
    Medium

    CVE-2025-8074

    Last Modified: 4 Feb 2026

    Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files with non-sensitive information via unspecified vectors.

    Published: 4 Dec 2025
    7.8
    High

    CVE-2025-54160

    Last Modified: 4 Feb 2026

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

    Published: 4 Dec 2025
    7.5
    High

    CVE-2025-54159

    Last Modified: 4 Feb 2026

    Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.

    Published: 4 Dec 2025
    7.8
    High

    CVE-2025-54158

    Last Modified: 24 Feb 2026

    Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

    Published: 4 Dec 2025
    6.3
    Medium

    CVE-2025-2848

    Last Modified: 9 Feb 2026

    A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

    Published: 4 Dec 2025
    2
    Low

    CVE-2025-14008

    Last Modified: 24 Feb 2026

    A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_domain of the component Project Domain Change Test. This manipulation of the argument v causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 Dec 2025
    7.2
    High

    CVE-2025-29846

    Last Modified: 26 Feb 2026

    A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

    Published: 4 Dec 2025