CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-54341

    Last Modified: 5 Dec 2025

    A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-63435

    Last Modified: 28 Nov 2025

    Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not require any authentication. This allows an unauthenticated remote attacker to freely download official update packages..

    Published: 24 Nov 2025
    9.8
    Critical

    CVE-2024-47856

    Last Modified: 30 Dec 2025

    In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.

    Published: 24 Nov 2025
    6.8
    Medium

    CVE-2025-63674

    Last Modified: 30 Dec 2025

    An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-54563

    Last Modified: 5 Dec 2025

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure.

    Published: 24 Nov 2025
    9.9
    Critical

    CVE-2025-54347

    Last Modified: 5 Dec 2025

    A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions.

    Published: 24 Nov 2025
    6.1
    Medium

    CVE-2025-64047

    Last Modified: 2 Dec 2025

    OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

    Published: 24 Nov 2025
    6.1
    Medium

    CVE-2025-64048

    Last Modified: 1 Dec 2025

    YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field.

    Published: 24 Nov 2025
    8.8
    High

    CVE-2025-63434

    Last Modified: 28 Nov 2025

    The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-60638

    Last Modified: 1 Dec 2025

    An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-65493

    Last Modified: 1 Dec 2025

    NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL.

    Published: 24 Nov 2025
    9.8
    Critical

    CVE-2025-63958

    Last Modified: 30 Dec 2025

    MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker can retrieve this information by accessing the endpoint directly, potentially leading to full system compromise. The vulnerability is due to missing access controls on a privileged administrative function.

    Published: 24 Nov 2025
    6.5
    Medium

    CVE-2025-63953

    Last Modified: 30 Dec 2025

    A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

    Published: 24 Nov 2025
    5.7
    Medium

    CVE-2025-63952

    Last Modified: 30 Dec 2025

    A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

    Published: 24 Nov 2025
    4.6
    Medium

    CVE-2025-63433

    Last Modified: 28 Nov 2025

    Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a static value within the application's code. An attacker with the ability to intercept network traffic can use this hardcoded key to decrypt, modify, and re-encrypt the update manifest, allowing them to direct the application to download a malicious update package.

    Published: 24 Nov 2025
    4.6
    Medium

    CVE-2025-63432

    Last Modified: 28 Nov 2025

    Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update server. An attacker on the same network can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack to intercept, decrypt, and modify traffic between the application and the update server. This serves as the basis for further attacks, including Remote Code Execution.

    Published: 24 Nov 2025
    4.6
    Medium

    CVE-2025-60917

    Last Modified: 28 Nov 2025

    A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65496

    Last Modified: 1 Dec 2025

    NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65497

    Last Modified: 1 Dec 2025

    NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65499

    Last Modified: 1 Dec 2025

    Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65501

    Last Modified: 1 Dec 2025

    Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL.

    Published: 24 Nov 2025
    5.3
    Medium

    CVE-2025-56423

    Last Modified: 28 Nov 2025

    An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages

    Published: 24 Nov 2025
    6.5
    Medium

    CVE-2025-60632

    Last Modified: 1 Dec 2025

    An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.

    Published: 24 Nov 2025
    5.4
    Medium

    CVE-2025-60916

    Last Modified: 28 Nov 2025

    A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65500

    Last Modified: 1 Dec 2025

    NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.

    Published: 24 Nov 2025
    4.3
    Medium

    CVE-2025-65502

    Last Modified: 12 Dec 2025

    Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.

    Published: 24 Nov 2025
    7.5
    High

    CVE-2025-54338

    Last Modified: 5 Dec 2025

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.

    Published: 24 Nov 2025
    2.1
    Low

    CVE-2025-13573

    Last Modified: 2 Dec 2025

    A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13572

    Last Modified: 24 Feb 2026

    A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

    Published: 23 Nov 2025
    6.4
    Medium

    CVE-2025-12800

    Last Modified: 22 Apr 2026

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. If the 'Unsafe features' option is explicitly enabled by an administrator, this issue becomes exploitable by Contributor+ attackers

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13571

    Last Modified: 2 Dec 2025

    A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /listorder.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13570

    Last Modified: 2 Dec 2025

    A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13569

    Last Modified: 2 Dec 2025

    A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13568

    Last Modified: 2 Dec 2025

    A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13567

    Last Modified: 2 Dec 2025

    A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 23 Nov 2025
    4.8
    Medium

    CVE-2025-13566

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_floating_window/run_cmd_as_plugin of the file nnn/src/nnn.c. The manipulation leads to double free. An attack has to be approached locally. The identifier of the patch is 2f07ccdf21e705377862e5f9dfa31e1694979ac7. It is suggested to install a patch to address this issue.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13565

    Last Modified: 26 Nov 2025

    A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.

    Published: 23 Nov 2025
    2.1
    Low

    CVE-2025-13564

    Last Modified: 2 Dec 2025

    A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13562

    Last Modified: 26 Nov 2025

    A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13561

    Last Modified: 26 Nov 2025

    A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

    Published: 23 Nov 2025
    1
    Low

    CVE-2025-54515

    Last Modified: 15 Apr 2026

    The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in the secure state instead of the non-secure state.

    Published: 23 Nov 2025
    8.6
    High

    CVE-2025-48507

    Last Modified: 15 Apr 2026

    The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13560

    Last Modified: 26 Nov 2025

    A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13557

    Last Modified: 24 Feb 2026

    A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Nov 2025
    7.3
    High

    CVE-2024-21923

    Last Modified: 15 Apr 2026

    Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

    Published: 23 Nov 2025
    7.3
    High

    CVE-2024-21922

    Last Modified: 15 Apr 2026

    A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13556

    Last Modified: 24 Feb 2026

    A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13555

    Last Modified: 24 Feb 2026

    A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 23 Nov 2025
    5.5
    Medium

    CVE-2025-13554

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 23 Nov 2025
    7.4
    High

    CVE-2025-13553

    Last Modified: 26 Nov 2025

    A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

    Published: 23 Nov 2025