CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2025-58482

    Last Modified: 26 Feb 2026

    Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.

    Published: 2 Dec 2025
    7.3
    High

    CVE-2025-58481

    Last Modified: 26 Feb 2026

    Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.

    Published: 2 Dec 2025
    4.3
    Medium

    CVE-2025-58480

    Last Modified: 5 Dec 2025

    Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

    Published: 2 Dec 2025
    4.3
    Medium

    CVE-2025-58479

    Last Modified: 5 Dec 2025

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

    Published: 2 Dec 2025
    4.3
    Medium

    CVE-2025-58478

    Last Modified: 5 Dec 2025

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

    Published: 2 Dec 2025
    4.3
    Medium

    CVE-2025-58477

    Last Modified: 5 Dec 2025

    Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

    Published: 2 Dec 2025
    4.2
    Medium

    CVE-2025-58476

    Last Modified: 5 Dec 2025

    Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

    Published: 2 Dec 2025
    5.6
    Medium

    CVE-2025-58475

    Last Modified: 5 Dec 2025

    Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 2 Dec 2025
    6.2
    Medium

    CVE-2025-21080

    Last Modified: 5 Dec 2025

    Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

    Published: 2 Dec 2025
    5.7
    Medium

    CVE-2025-21072

    Last Modified: 26 Feb 2026

    Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 2 Dec 2025
    6.8
    Medium

    CVE-2025-59705

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.

    Published: 2 Dec 2025
    4.6
    Medium

    CVE-2025-59704

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.

    Published: 2 Dec 2025
    7.2
    High

    CVE-2025-59702

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.

    Published: 2 Dec 2025
    3.9
    Low

    CVE-2025-59700

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection).

    Published: 2 Dec 2025
    7.2
    High

    CVE-2025-59697

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-59695

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.

    Published: 2 Dec 2025
    6.8
    Medium

    CVE-2025-59694

    Last Modified: 26 Aug 2026

    The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.

    Published: 2 Dec 2025
    6.1
    Medium

    CVE-2025-63872

    Last Modified: 14 Jan 2026

    DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content.

    Published: 2 Dec 2025
    6.8
    Medium

    CVE-2025-59699

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.

    Published: 2 Dec 2025
    3.5
    Low

    CVE-2025-65858

    Last Modified: 23 Dec 2025

    A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

    Published: 2 Dec 2025
    7.5
    High

    CVE-2025-65844

    Last Modified: 6 Dec 2025

    EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-60736

    Last Modified: 5 Dec 2025

    code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

    Published: 2 Dec 2025
    6.5
    Medium

    CVE-2025-65657

    Last Modified: 19 Dec 2025

    FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-60854

    Last Modified: 6 Dec 2025

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-65896

    Last Modified: 19 Dec 2025

    SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

    Published: 2 Dec 2025
    6.1
    Medium

    CVE-2025-65881

    Last Modified: 5 Dec 2025

    Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

    Published: 2 Dec 2025
    5.4
    Medium

    CVE-2025-64070

    Last Modified: 3 Dec 2025

    Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject Description field.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-65656

    Last Modified: 4 Dec 2025

    dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

    Published: 2 Dec 2025
    6.8
    Medium

    CVE-2025-59698

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-58386

    Last Modified: 19 Dec 2025

    In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged account and escalate its privileges. While manipulating this request, the Power User can also change the target account's password, effectively taking full control of it.

    Published: 2 Dec 2025
    6.1
    Medium

    CVE-2025-65215

    Last Modified: 5 Dec 2025

    Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-59693

    Last Modified: 26 Aug 2026

    The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving evidence, and accessing the JTAG connector. This is called F02.

    Published: 2 Dec 2025
    6.5
    Medium

    CVE-2025-65380

    Last Modified: 4 Dec 2025

    PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.

    Published: 2 Dec 2025
    6.5
    Medium

    CVE-2025-65379

    Last Modified: 4 Dec 2025

    PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is then concatenated directly into a backend SQL query.

    Published: 2 Dec 2025
    9.8
    Critical

    CVE-2025-65358

    Last Modified: 4 Dec 2025

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

    Published: 2 Dec 2025
    9.1
    Critical

    CVE-2025-59703

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and all fixing screws from the device without damaging it. This is called an F14 attack.

    Published: 2 Dec 2025
    4.1
    Medium

    CVE-2025-59701

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted).

    Published: 2 Dec 2025
    6.1
    Medium

    CVE-2025-65187

    Last Modified: 23 Dec 2025

    A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

    Published: 2 Dec 2025
    6.1
    Medium

    CVE-2025-65186

    Last Modified: 4 Dec 2025

    Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.

    Published: 2 Dec 2025
    7.5
    High

    CVE-2025-65877

    Last Modified: 19 Dec 2025

    Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 'title' parameter in com.wanli.lvzhoucms.service.ContentService#findPage. The parameter is concatenated directly into a dynamic SQL query without sanitization or prepared statements, enabling attackers to read sensitive data from the database.

    Published: 2 Dec 2025
    3.2
    Low

    CVE-2025-59696

    Last Modified: 26 Aug 2026

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board.

    Published: 2 Dec 2025
    7.1
    High

    CVE-2025-66448

    Last Modified: 3 Dec 2025

    vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.

    Published: 1 Dec 2025
    9.8
    Critical

    CVE-2025-66401

    Last Modified: 6 Feb 2026

    MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to a system shell via execSync without sanitization. This allows an attacker to execute arbitrary commands on the host machine by appending shell metacharacters to the URL.

    Published: 1 Dec 2025
    6.9
    Medium

    CVE-2025-66415

    Last Modified: 6 Feb 2026

    fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.

    Published: 1 Dec 2025
    8.5
    High

    CVE-2025-66412

    Last Modified: 2 Jun 2026

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.

    Published: 1 Dec 2025
    8.7
    High

    CVE-2025-66410

    Last Modified: 6 Feb 2026

    Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.

    Published: 1 Dec 2025
    6.9
    Medium

    CVE-2025-66405

    Last Modified: 20 Feb 2026

    Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

    Published: 1 Dec 2025
    4.6
    Medium

    CVE-2025-66403

    Last Modified: 7 Jan 2026

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG files. The application accepts user-supplied SVG uploads without sanitizing or restricting embedded script content. When a malicious SVG containing inline JavaScript or event-based payloads is uploaded, it is later rendered directly in the browser whenever viewed within the application. Because SVGs are XML-based and allow scripting, they execute in the origin context of the application, enabling full stored XSS. This vulnerability is fixed in 2.2.3.

    Published: 1 Dec 2025
    6.9
    Medium

    CVE-2025-66400

    Last Modified: 6 Feb 2026

    mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.

    Published: 1 Dec 2025
    5.1
    Medium

    CVE-2025-66313

    Last Modified: 3 Dec 2025

    ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value is incorporated into a SQL query without proper parameterization. The issue allows data exfiltration and modification via blind techniques.

    Published: 1 Dec 2025