CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2025-12741

    Last Modified: 15 Apr 2026

    A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.12.108+ * 24.18.200+ * 25.0.78+ * 25.6.65+ * 25.8.47+ * 25.12.10+ * 25.14+

    Published: 24 Nov 2025
    7.7
    High

    CVE-2025-12740

    Last Modified: 15 Apr 2026

    A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 25.0.93+ * 25.6.84+ * 25.12.42+ * 25.14.50+ * 25.16.44+

    Published: 24 Nov 2025
    5.1
    Medium

    CVE-2025-41087

    Last Modified: 15 Apr 2026

    Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not properly sanitized. This allows to the attackers to embed malicious scripts in SVG files such as image profiles, which are then stored on the server and executed in the context of any user who accesses the compromised resource.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-41729

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service.

    Published: 24 Nov 2025
    7.3
    High

    CVE-2025-12739

    Last Modified: 15 Apr 2026

    An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.18.201+ * 25.0.79+ * 25.6.66+ * 25.12.7+ * 25.16.0+ * 25.18.0+ * 25.20.0+

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66187

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66179

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66180

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66181

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66182

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66183

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66184

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66185

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-66186

    Last Modified: 25 Nov 2025

    Not used

    Published: 24 Nov 2025
    Unknown

    CVE-2025-13598

    Last Modified: 24 Nov 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 24 Nov 2025
    2.7
    Low

    CVE-2025-13596

    Last Modified: 15 Apr 2026

    A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. This may expose internal filesystem paths, SQL queries, database connection details, or environment configuration data to remote unauthenticated attackers. This issue allows information gathering and reconnaissance but does not enable direct system compromise.

    Published: 24 Nov 2025
    Unknown

    CVE-2025-13594

    Last Modified: 24 Nov 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13588

    Last Modified: 15 Apr 2026

    A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading to version 2.8.1 is sufficient to resolve this issue. The patch is named c70bfb8d36b47bfd64c5ec73917e1d9ddb97af92. It is suggested to upgrade the affected component.

    Published: 24 Nov 2025
    2
    Low

    CVE-2025-13586

    Last Modified: 2 Dec 2025

    A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the argument txtconfirm_password causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

    Published: 24 Nov 2025
    7.1
    High

    CVE-2025-12629

    Last Modified: 28 Apr 2026

    The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 24 Nov 2025
    4.7
    Medium

    CVE-2025-12569

    Last Modified: 15 Apr 2026

    The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

    Published: 24 Nov 2025
    5.9
    Medium

    CVE-2025-12394

    Last Modified: 15 Apr 2026

    The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

    Published: 24 Nov 2025
    7.1
    High

    CVE-2024-14015

    Last Modified: 15 Apr 2026

    The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 24 Nov 2025
    5.5
    Medium

    CVE-2025-13585

    Last Modified: 7 Dec 2025

    A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

    Published: 24 Nov 2025
    2
    Low

    CVE-2025-13584

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the argument entry.description/time_entry.description leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.4.1 is able to resolve this issue. The identifier of the patch is 7dec94c9d1f3e513e0ee38ba68caaba628e08582. Upgrading the affected component is advised.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-7402

    Last Modified: 21 Apr 2026

    The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘site_id’ parameter in all versions up to, and including, 4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 24 Nov 2025
    5.5
    Medium

    CVE-2025-13583

    Last Modified: 2 Dec 2025

    A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation of the argument Fname can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

    Published: 24 Nov 2025
    5.5
    Medium

    CVE-2025-13582

    Last Modified: 2 Dec 2025

    A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php of the component GET Parameter Handler. Performing manipulation of the argument Product results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13581

    Last Modified: 1 Dec 2025

    A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

    Published: 24 Nov 2025
    5.1
    Medium

    CVE-2025-13589

    Last Modified: 15 Apr 2026

    FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13580

    Last Modified: 24 Feb 2026

    A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13579

    Last Modified: 24 Feb 2026

    A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 24 Nov 2025
    5.5
    Medium

    CVE-2025-13578

    Last Modified: 24 Feb 2026

    A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Nov 2025
    2
    Low

    CVE-2025-13577

    Last Modified: 24 Feb 2026

    A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13576

    Last Modified: 2 Dec 2025

    A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used. Multiple endpoints are affected.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13575

    Last Modified: 2 Dec 2025

    A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.

    Published: 24 Nov 2025
    2
    Low

    CVE-2025-13574

    Last Modified: 2 Dec 2025

    A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

    Published: 24 Nov 2025
    9.8
    Critical

    CVE-2025-40212

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root filesystem" which is used by NFSv4 to find the various exported filesystems using LOOKUP requests from a known root filehandle. NFSv3 uses the MOUNT protocol to find those exported filesystems and so is not given access to the pseudo root filesystem. If a v3 (or v2) client uses a filehandle from that filesystem, nfsd_set_fh_dentry() will report an error, but still stores the export in "struct svc_fh" even though it also drops the reference (exp_put()). This means that when fh_put() is called an extra reference will be dropped which can lead to use-after-free and possible denial of service. Normal NFS usage will not provide a pseudo-root filehandle to a v3 client. This bug can only be triggered by the client synthesising an incorrect filehandle. To fix this we move the assignments to the svc_fh later, after all possible error cases have been detected.

    Published: 24 Nov 2025
    7.8
    High

    CVE-2025-40213

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error.

    Published: 24 Nov 2025
    6.1
    Medium

    CVE-2025-63498

    Last Modified: 30 Dec 2025

    alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

    Published: 24 Nov 2025
    6.5
    Medium

    CVE-2025-63914

    Last Modified: 30 Dec 2025

    An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.

    Published: 24 Nov 2025
    8.8
    High

    CVE-2025-56400

    Last Modified: 30 Dec 2025

    Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms.

    Published: 24 Nov 2025
    4.6
    Medium

    CVE-2025-60914

    Last Modified: 28 Nov 2025

    Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.

    Published: 24 Nov 2025
    5.5
    Medium

    CVE-2025-65503

    Last Modified: 11 Dec 2025

    Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65498

    Last Modified: 1 Dec 2025

    NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.

    Published: 24 Nov 2025
    7.6
    High

    CVE-2025-56401

    Last Modified: 30 Dec 2025

    ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.

    Published: 24 Nov 2025
    8.1
    High

    CVE-2025-60915

    Last Modified: 28 Nov 2025

    An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-65495

    Last Modified: 1 Dec 2025

    Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-65494

    Last Modified: 1 Dec 2025

    NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.

    Published: 24 Nov 2025
    6.5
    Medium

    CVE-2025-60633

    Last Modified: 1 Dec 2025

    An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

    Published: 24 Nov 2025