CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-66258

    Last Modified: 3 Dec 2025

    Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are directly concatenated into `patchlist.xml` without encoding, allowing injection of malicious JavaScript payloads via crafted filenames (e.g., `<img src=x onerror=alert()>.bin`). The XSS executes when ajax.js processes and renders the XML file.

    Published: 26 Nov 2025
    9.2
    Critical

    CVE-2025-66257

    Last Modified: 3 Dec 2025

    Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletepatch parameter allows unauthenticated deletion of arbitrary files. The `deletepatch` parameter in `patch_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/patch/` directory without sanitization or access control checks.

    Published: 26 Nov 2025
    9.9
    Critical

    CVE-2025-66256

    Last Modified: 3 Dec 2025

    Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows uploading malicious files. The `/var/tdf/patch_contents.php` endpoint allows unauthenticated arbitrary file uploads without file type validation, MIME checking, or size restrictions beyond 16MB, enabling attackers to upload malicious files.

    Published: 26 Nov 2025
    9.9
    Critical

    CVE-2025-66255

    Last Modified: 3 Dec 2025

    Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.  The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution

    Published: 26 Nov 2025
    7.8
    High

    CVE-2025-66254

    Last Modified: 3 Dec 2025

    Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated deletion of arbitrary files.  The `deleteupgrade` parameter in `/var/www/upgrade_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/upload/` without any extension restriction or path sanitization, enabling attackers to remove critical system files.

    Published: 26 Nov 2025
    9.9
    Critical

    CVE-2025-66253

    Last Modified: 3 Dec 2025

    Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET["filename"]` directly into `exec()` without sanitization or shell escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, etc.) to achieve remote code execution as the web server user (likely root).

    Published: 26 Nov 2025
    8.4
    High

    CVE-2025-66252

    Last Modified: 3 Dec 2025

    Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when unlink() fails in status_contents.php causing DoS. Due to the fact that the unlink operation is done in a while loop; if an immutable file is specified or otherwise a file in which the process has no permissions to delete; it would repeatedly attempt to do in a loop.

    Published: 26 Nov 2025
    7.7
    High

    CVE-2025-66251

    Last Modified: 3 Dec 2025

    Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden parameter allows path traversal deletion of arbitrary .tgz files.

    Published: 26 Nov 2025
    9.2
    Critical

    CVE-2025-66250

    Last Modified: 3 Dec 2025

    Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Allows unauthenticated arbitrary file upload via /var/tdf/status_contents.php.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-64657

    Last Modified: 26 Feb 2026

    Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

    Published: 26 Nov 2025
    9.4
    Critical

    CVE-2025-64656

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

    Published: 26 Nov 2025
    3.3
    Low

    CVE-2025-65681

    Last Modified: 30 Dec 2025

    An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-65276

    Last Modified: 30 Dec 2025

    An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an attacker can directly access the admin dashboard without valid credentials. This allows full administrative control including viewing/modifying user accounts, managing orders, changing payments, and editing product listings. Successful exploitation can lead to information disclosure, data manipulation, and privilege escalation.

    Published: 26 Nov 2025
    7.5
    High

    CVE-2025-55471

    Last Modified: 5 Dec 2025

    Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

    Published: 26 Nov 2025
    6.5
    Medium

    CVE-2025-65238

    Last Modified: 2 Jan 2026

    Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with low-level privileges to dump user records and access sensitive information.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-65236

    Last Modified: 2 Jan 2026

    OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.

    Published: 26 Nov 2025
    8
    High

    CVE-2025-65202

    Last Modified: 5 Dec 2025

    TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.

    Published: 26 Nov 2025
    6.5
    Medium

    CVE-2025-63938

    Last Modified: 2 Jan 2026

    Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-50402

    Last Modified: 2 Jan 2026

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-55469

    Last Modified: 5 Dec 2025

    Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-26155

    Last Modified: 30 Dec 2025

    NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

    Published: 26 Nov 2025
    7.5
    High

    CVE-2025-65672

    Last Modified: 5 Dec 2025

    Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.

    Published: 26 Nov 2025
    8.8
    High

    CVE-2025-45311

    Last Modified: 15 Apr 2026

    Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behaving in accordance with its intended privilege model.

    Published: 26 Nov 2025
    6.1
    Medium

    CVE-2025-65237

    Last Modified: 2 Jan 2026

    A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.

    Published: 26 Nov 2025
    4.3
    Medium

    CVE-2025-65239

    Last Modified: 30 Dec 2025

    Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.11 allows attackers with low-level privileges to read server logs.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-65235

    Last Modified: 2 Jan 2026

    OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-50399

    Last Modified: 2 Jan 2026

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

    Published: 26 Nov 2025
    5.4
    Medium

    CVE-2025-65675

    Last Modified: 5 Dec 2025

    Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

    Published: 26 Nov 2025
    5.4
    Medium

    CVE-2025-65676

    Last Modified: 3 Dec 2025

    Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

    Published: 26 Nov 2025
    9.1
    Critical

    CVE-2025-65669

    Last Modified: 3 Dec 2025

    An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.

    Published: 26 Nov 2025
    8.8
    High

    CVE-2025-56396

    Last Modified: 4 Dec 2025

    An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

    Published: 26 Nov 2025
    4.3
    Medium

    CVE-2025-65670

    Last Modified: 3 Dec 2025

    An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access.

    Published: 26 Nov 2025
    7.5
    High

    CVE-2025-46175

    Last Modified: 4 Dec 2025

    Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.

    Published: 26 Nov 2025
    3.2
    Low

    CVE-2025-55174

    Last Modified: 15 Apr 2026

    In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.

    Published: 26 Nov 2025
    7.5
    High

    CVE-2025-46174

    Last Modified: 4 Dec 2025

    Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.

    Published: 26 Nov 2025
    9.8
    Critical

    CVE-2025-50433

    Last Modified: 29 Dec 2025

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

    Published: 26 Nov 2025
    7.5
    High

    CVE-2025-65278

    Last Modified: 30 Dec 2025

    An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.

    Published: 26 Nov 2025
    6.7
    Medium

    CVE-2025-59820

    Last Modified: 15 Apr 2026

    In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.

    Published: 26 Nov 2025
    5.4
    Medium

    CVE-2025-65963

    Last Modified: 15 Apr 2026

    Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions 0.16.11 and 0.17.2.

    Published: 25 Nov 2025
    6.6
    Medium

    CVE-2025-66019

    Last Modified: 15 Apr 2026

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

    Published: 25 Nov 2025
    8.8
    High

    CVE-2025-65957

    Last Modified: 15 Apr 2026

    Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may inadvertently leak sensitive data (e.g., by failing to redact data in summary embeds or logs). This issue has been patched via commit dffe050.

    Published: 25 Nov 2025
    6.5
    Medium

    CVE-2025-65956

    Last Modified: 3 Dec 2025

    Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed in their browser. The issue is persistent and impacts privileged administrative workflows. This issue has been patched in version 2.2.0.

    Published: 25 Nov 2025
    6
    Medium

    CVE-2025-65953

    Last Modified: 15 Apr 2026

    NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UAF) vulnerability exists in the TCP transport component of NanoMQ, which relies on the underlying NanoNNG library (specifically in src/sp/transport/mqtt/broker_tcp.c). The vulnerability is due to improper resource management and premature cleanup of message and pipe structures under specific malformed MQTTV5 retain message traffic conditions. This issue has been patched in version 0.22.5.

    Published: 25 Nov 2025
    8.7
    High

    CVE-2025-65952

    Last Modified: 15 Apr 2026

    Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched in version 2.8.0.

    Published: 25 Nov 2025
    9.8
    Critical

    CVE-2025-13597

    Last Modified: 21 Apr 2026

    The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.0.11. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the affected site's server which may make remote code execution possible.

    Published: 25 Nov 2025
    9.8
    Critical

    CVE-2025-13595

    Last Modified: 21 Apr 2026

    The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.10.8. This makes it possible for unauthenticated attackers to download arbitrary GitHub repositories and overwrite plugin files on the affected site's server which may make remote code execution possible.

    Published: 25 Nov 2025
    2.7
    Low

    CVE-2025-65942

    Last Modified: 15 Apr 2026

    VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.

    Published: 25 Nov 2025
    5.1
    Medium

    CVE-2025-64713

    Last Modified: 3 Dec 2025

    WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is encountered, frame_ref_bottom is expanded but frame_offset_bottom may not be. If this is immediately followed by an if opcode that triggers preserve_local_for_block, the function traverses arrays using stack_cell_num as the upper bound, causing out-of-bounds access to frame_offset_bottom since it wasn't expanded to match the increased stack_cell_num. This issue has been patched in version 2.4.4.

    Published: 25 Nov 2025
    4.7
    Medium

    CVE-2025-64704

    Last Modified: 3 Dec 2025

    WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.

    Published: 25 Nov 2025
    6.1
    Medium

    CVE-2025-21621

    Last Modified: 3 Dec 2025

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim's browser through specially crafted SLD_BODY parameters. This issue has been patched in version 2.25.0.

    Published: 25 Nov 2025