CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-12138

    Last Modified: 15 Apr 2026

    The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.0.6. This is due to the plugin relying on a user-controlled Content-Type HTTP header to validate file uploads in the 'uimptr_import_image_from_url()' function which writes the file to the server before performing proper validation. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible via the uploaded PHP file.

    Published: 21 Nov 2025
    6.4
    Medium

    CVE-2025-11765

    Last Modified: 15 Apr 2026

    The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_width' shortcode attributes in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Nov 2025
    5.3
    Medium

    CVE-2025-12170

    Last Modified: 22 Apr 2026

    The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_log' AJAX endpoint in all versions up to, and including, 2.8.10. This makes it possible for unauthenticated attackers to clear log files.

    Published: 21 Nov 2025
    4.3
    Medium

    CVE-2025-12086

    Last Modified: 22 Apr 2026

    The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other users refund requests.

    Published: 21 Nov 2025
    6.4
    Medium

    CVE-2025-12661

    Last Modified: 22 Apr 2026

    The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the 'pollcaster' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Nov 2025
    8.1
    High

    CVE-2025-13322

    Last Modified: 22 Apr 2026

    The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not properly validating user-supplied file paths in the `audio_upload` parameter before passing them to `unlink()`. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when critical files like wp-config.php are deleted.

    Published: 21 Nov 2025
    6.4
    Medium

    CVE-2025-12660

    Last Modified: 22 Apr 2026

    The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'wallwisher' shortcode in all versions up to, and including, 1.3. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Nov 2025
    6.1
    Medium

    CVE-2025-12746

    Last Modified: 22 Apr 2026

    The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 21 Nov 2025
    8.4
    High

    CVE-2025-64695

    Last Modified: 2 Dec 2025

    Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer.

    Published: 21 Nov 2025
    6.9
    Medium

    CVE-2025-64299

    Last Modified: 2 Dec 2025

    LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.

    Published: 21 Nov 2025
    6.9
    Medium

    CVE-2025-62687

    Last Modified: 2 Dec 2025

    Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.

    Published: 21 Nov 2025
    5.3
    Medium

    CVE-2025-62189

    Last Modified: 4 Dec 2025

    LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.

    Published: 21 Nov 2025
    4.8
    Medium

    CVE-2025-61949

    Last Modified: 5 Dec 2025

    LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.

    Published: 21 Nov 2025
    6.8
    Medium

    CVE-2025-58097

    Last Modified: 5 Dec 2025

    The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.

    Published: 21 Nov 2025
    7.8
    High

    CVE-2025-13499

    Last Modified: 27 Mar 2026

    Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

    Published: 21 Nov 2025
    5
    Medium

    CVE-2025-9825

    Last Modified: 2 Dec 2025

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

    Published: 21 Nov 2025
    4.3
    Medium

    CVE-2025-12169

    Last Modified: 21 Apr 2026

    The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_eh_crm_settings_empty_scheduled_actions' AJAX Action in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the scheduled triggers option.

    Published: 21 Nov 2025
    4.3
    Medium

    CVE-2025-12022

    Last Modified: 22 Apr 2026

    The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_restore_trash' AJAX endpoint in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to restore all deleted tickets.

    Published: 21 Nov 2025
    4.3
    Medium

    CVE-2025-12085

    Last Modified: 22 Apr 2026

    The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_empty_trash' function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to empty the ticket trash.

    Published: 21 Nov 2025
    4.3
    Medium

    CVE-2025-12023

    Last Modified: 22 Apr 2026

    The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_crm_restore_data() function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to restore tickets.

    Published: 21 Nov 2025
    5.3
    Medium

    CVE-2025-11368

    Last Modified: 22 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.

    Published: 21 Nov 2025
    9.3
    Critical

    CVE-2025-64310

    Last Modified: 15 Apr 2026

    EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.

    Published: 21 Nov 2025
    8
    High

    CVE-2025-64762

    Last Modified: 11 Dec 2025

    The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled, this can result in session tokens being included in cached responses and subsequently served to multiple users. Next.js applications deployed on Vercel are unaffected unless they manually enable CDN caching by setting cache headers on authenticated paths. Patched in authkit-nextjs 2.11.1, which applies anti-caching headers to all responses behind authentication.

    Published: 21 Nov 2025
    5.8
    Medium

    CVE-2025-64751

    Last Modified: 31 Dec 2025

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This issue has been patched in version 1.11.1.

    Published: 21 Nov 2025
    8.3
    High

    CVE-2025-62372

    Last Modified: 4 Dec 2025

    vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

    Published: 21 Nov 2025
    6.5
    Medium

    CVE-2025-62426

    Last Modified: 4 Dec 2025

    vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request parameter that is used in the code before it is properly validated against the chat template. With the right chat_template_kwargs parameters, it is possible to block processing of the API server for long periods of time, delaying all other requests. This issue has been patched in version 0.11.1.

    Published: 21 Nov 2025
    8.8
    High

    CVE-2025-62164

    Last Modified: 4 Dec 2025

    vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When processing user-supplied prompt embeddings, the endpoint loads serialized tensors using torch.load() without sufficient validation. Due to a change introduced in PyTorch 2.8.0, sparse tensor integrity checks are disabled by default. As a result, maliciously crafted tensors can bypass internal bounds checks and trigger an out-of-bounds memory write during the call to to_dense(). This memory corruption can crash vLLM and potentially lead to code execution on the server hosting vLLM. This issue has been patched in version 0.11.1.

    Published: 21 Nov 2025
    8.7
    High

    CVE-2025-64755

    Last Modified: 4 Dec 2025

    Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.

    Published: 21 Nov 2025
    5.5
    Medium

    CVE-2025-13485

    Last Modified: 24 Nov 2025

    A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

    Published: 21 Nov 2025
    7
    High

    CVE-2025-40211

    Last Modified: 16 Jun 2026

    In the Linux kernel, the following vulnerability has been resolved: ACPI: video: Fix use-after-free in acpi_video_switch_brightness() The switch_brightness_work delayed work accesses device->brightness and device->backlight, freed by acpi_video_dev_unregister_backlight() during device removal. If the work executes after acpi_video_bus_unregister_backlight() frees these resources, it causes a use-after-free when acpi_video_switch_brightness() dereferences device->brightness or device->backlight. Fix this by calling cancel_delayed_work_sync() for each device's switch_brightness_work in acpi_video_bus_remove_notify_handler() after removing the notify handler that queues the work. This ensures the work completes before the memory is freed. [ rjw: Changelog edit ]

    Published: 21 Nov 2025
    7.5
    High

    CVE-2025-40210

    Last Modified: 15 Apr 2026

    In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've found that pynfs COMP6 now leaves the connection or lease in a strange state, which causes CLOSE9 to hang indefinitely. I've dug into it a little, but I haven't been able to root-cause it yet. However, I bisected to commit 48aab1606fa8 ("NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"). Tianshuo Han also reports a potential vulnerability when decoding an NFSv4 COMPOUND. An attacker can place an arbitrarily large op count in the COMPOUND header, which results in: [ 51.410584] nfsd: vmalloc error: size 1209533382144, exceeds total pages, mode:0xdc0(GFP_KERNEL|__GFP_ZERO), nodemask=(null),cpuset=/,mems_allowed=0 when NFSD attempts to allocate the COMPOUND op array. Let's restore the operation-per-COMPOUND limit, but increased to 200 for now.

    Published: 21 Nov 2025
    5.5
    Medium

    CVE-2025-40209

    Last Modified: 15 Apr 2026

    In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation When btrfs_add_qgroup_relation() is called with invalid qgroup levels (src >= dst), the function returns -EINVAL directly without freeing the preallocated qgroup_list structure passed by the caller. This causes a memory leak because the caller unconditionally sets the pointer to NULL after the call, preventing any cleanup. The issue occurs because the level validation check happens before the mutex is acquired and before any error handling path that would free the prealloc pointer. On this early return, the cleanup code at the 'out' label (which includes kfree(prealloc)) is never reached. In btrfs_ioctl_qgroup_assign(), the code pattern is: prealloc = kzalloc(sizeof(*prealloc), GFP_KERNEL); ret = btrfs_add_qgroup_relation(trans, sa->src, sa->dst, prealloc); prealloc = NULL; // Always set to NULL regardless of return value ... kfree(prealloc); // This becomes kfree(NULL), does nothing When the level check fails, 'prealloc' is never freed by either the callee or the caller, resulting in a 64-byte memory leak per failed operation. This can be triggered repeatedly by an unprivileged user with access to a writable btrfs mount, potentially exhausting kernel memory. Fix this by freeing prealloc before the early return, ensuring prealloc is always freed on all error paths.

    Published: 21 Nov 2025
    1.9
    Low

    CVE-2025-13484

    Last Modified: 24 Feb 2026

    A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.

    Published: 20 Nov 2025
    8.3
    High

    CVE-2025-62459

    Last Modified: 26 Feb 2026

    Microsoft Defender Portal Spoofing Vulnerability

    Published: 20 Nov 2025
    8
    High

    CVE-2025-64660

    Last Modified: 26 Feb 2026

    Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

    Published: 20 Nov 2025
    8.6
    High

    CVE-2025-62207

    Last Modified: 26 Feb 2026

    Azure Monitor Elevation of Privilege Vulnerability

    Published: 20 Nov 2025
    10
    Critical

    CVE-2025-49752

    Last Modified: 26 Feb 2026

    Azure Bastion Elevation of Privilege Vulnerability

    Published: 20 Nov 2025
    9.8
    Critical

    CVE-2025-59245

    Last Modified: 26 Feb 2026

    Microsoft SharePoint Online Elevation of Privilege Vulnerability

    Published: 20 Nov 2025
    8.8
    High

    CVE-2025-64655

    Last Modified: 26 Feb 2026

    Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Nov 2025
    8.8
    High

    CVE-2025-36072

    Last Modified: 15 Dec 2025

    IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.

    Published: 20 Nov 2025
    7.5
    High

    CVE-2025-13087

    Last Modified: 15 Apr 2026

    A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When a POST request is executed against the vulnerable endpoint, the application reads certain header details and unsafely uses these values to build commands, allowing an attacker with administrative privileges to inject arbitrary commands that execute as root.

    Published: 20 Nov 2025
    6.1
    Medium

    CVE-2025-36153

    Last Modified: 21 Nov 2025

    IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-36158

    Last Modified: 21 Nov 2025

    IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

    Published: 20 Nov 2025
    6.2
    Medium

    CVE-2025-36159

    Last Modified: 21 Nov 2025

    IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

    Published: 20 Nov 2025
    5.3
    Medium

    CVE-2025-36160

    Last Modified: 21 Nov 2025

    IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

    Published: 20 Nov 2025
    7
    High

    CVE-2025-62674

    Last Modified: 15 Apr 2026

    The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

    Published: 20 Nov 2025
    7
    High

    CVE-2025-64770

    Last Modified: 15 Apr 2026

    The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

    Published: 20 Nov 2025
    4.8
    Medium

    CVE-2025-35029

    Last Modified: 31 Dec 2025

    Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.

    Published: 20 Nov 2025
    5.4
    Medium

    CVE-2025-52668

    Last Modified: 2 Dec 2025

    Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

    Published: 20 Nov 2025
    8.8
    High

    CVE-2025-48986

    Last Modified: 25 Nov 2025

    Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

    Published: 20 Nov 2025