CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2025-48987

    Last Modified: 25 Nov 2025

    Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

    Published: 20 Nov 2025
    5.4
    Medium

    CVE-2025-55123

    Last Modified: 5 Dec 2025

    Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

    Published: 20 Nov 2025
    4.3
    Medium

    CVE-2025-52671

    Last Modified: 2 Dec 2025

    Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

    Published: 20 Nov 2025
    2.7
    Low

    CVE-2025-52666

    Last Modified: 2 Dec 2025

    Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

    Published: 20 Nov 2025
    4.3
    Medium

    CVE-2025-52669

    Last Modified: 2 Dec 2025

    Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

    Published: 20 Nov 2025
    6.1
    Medium

    CVE-2025-55124

    Last Modified: 26 Nov 2025

    Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

    Published: 20 Nov 2025
    6.5
    Medium

    CVE-2025-52670

    Last Modified: 2 Dec 2025

    Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

    Published: 20 Nov 2025
    5.4
    Medium

    CVE-2025-52667

    Last Modified: 2 Dec 2025

    Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

    Published: 20 Nov 2025
    6.5
    Medium

    CVE-2025-55126

    Last Modified: 14 Jan 2026

    HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS

    Published: 20 Nov 2025
    5.4
    Medium

    CVE-2025-55127

    Last Modified: 14 Jan 2026

    HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially leading to confusion.

    Published: 20 Nov 2025
    6.5
    Medium

    CVE-2025-55128

    Last Modified: 14 Jan 2026

    HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.

    Published: 20 Nov 2025
    9.4
    Critical

    CVE-2025-10571

    Last Modified: 15 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.

    Published: 20 Nov 2025
    3.3
    Low

    CVE-2025-64524

    Last Modified: 15 Dec 2025

    cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing maliciously crafted input data. This issue can be exploited to trigger memory corruption, potentially leading to arbitrary code execution. This issue has been patched via commit 956283c.

    Published: 20 Nov 2025
    8.9
    High

    CVE-2025-64428

    Last Modified: 24 Nov 2025

    Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed in version 2.10.17.

    Published: 20 Nov 2025
    6.9
    Medium

    CVE-2025-64185

    Last Modified: 15 Apr 2026

    Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

    Published: 20 Nov 2025
    4.3
    Medium

    CVE-2025-62724

    Last Modified: 15 Apr 2026

    Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites that use the file browser allowlists in all current versions of OOD. However, files accessed are still protected by the UNIX permissions. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

    Published: 20 Nov 2025
    6.8
    Medium

    CVE-2025-62709

    Last Modified: 25 Nov 2025

    ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from the incoming HTTP Host header when the configuration base_url is not set. Because Host is a client-controlled header, an attacker can supply an arbitrary Host value. This allows an attacker to cause password-reset links (sent by forget.php) to be generated with the attacker’s domain. If a victim follows that link and enters their activation code on the attacker-controlled domain, the attacker can capture the code and use it to reset the victim’s password and take over the account. This issue has been patched in version 5.5.2#162.

    Published: 20 Nov 2025
    7.3
    High

    CVE-2025-12121

    Last Modified: 10 Dec 2025

    Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

    Published: 20 Nov 2025
    7.3
    High

    CVE-2025-12120

    Last Modified: 10 Dec 2025

    Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of untrusted Lua code if a user opens a malicious project, potentially leading to arbitrary code execution with the privileges of the Lite XL process.

    Published: 20 Nov 2025
    5.6
    Medium

    CVE-2025-13437

    Last Modified: 15 Apr 2026

    When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_modules. Due to a logic error in src/cli.ts (linkNodeModules / cleanup), the function returns the target path instead of the alias (symlink path). The later cleanup routine removes what it received, which deletes the target directory itself. Result: zx can delete an external <path>/node_modules outside the current working directory.

    Published: 20 Nov 2025
    6.9
    Medium

    CVE-2025-62875

    Last Modified: 15 Jan 2026

    An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-62731

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with special privileges are able to access this endpoint. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    8.7
    High

    CVE-2025-62730

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-62729

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-62297

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening edited page. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-62296

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-62295

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    8.7
    High

    CVE-2025-62294

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    5.3
    Medium

    CVE-2025-62293

    Last Modified: 24 Nov 2025

    SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status. This issue was fixed in version 1.55.

    Published: 20 Nov 2025
    9.3
    Critical

    CVE-2025-34320

    Last Modified: 14 Jul 2026

    BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allows unauthenticated directory traversal sequences to cause the server to read arbitrary system files accessible to the account running the service. Retrieved configuration artifacts may contain account credentials used for BBj Enterprise Manager; possession of these credentials enables administrative access and use of legitimate management functionality that can result in execution of system commands under the service account. Depending on the operating system and the privileges of the BBj service account, this issue may also allow access to other sensitive files on the host, including operating system or application data, potentially exposing additional confidential information.

    Published: 20 Nov 2025
    1.9
    Low

    CVE-2025-13425

    Last Modified: 15 Apr 2026

    A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (denial of service) in OSV-SCALIBR.

    Published: 20 Nov 2025
    5.9
    Medium

    CVE-2025-36161

    Last Modified: 24 Nov 2025

    IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 20 Nov 2025
    7.2
    High

    CVE-2025-0645

    Last Modified: 6 Jun 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Pyxis Signage: through 31012025.

    Published: 20 Nov 2025
    4.8
    Medium

    CVE-2025-13469

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross site scripting. The attack can be initiated remotely. You should upgrade the affected component.

    Published: 20 Nov 2025
    2.1
    Low

    CVE-2025-13468

    Last Modified: 21 Nov 2025

    A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

    Published: 20 Nov 2025
    7.2
    High

    CVE-2025-0643

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows Stored XSS. This issue affects Pyxis Signage: through 31012025.

    Published: 20 Nov 2025
    6.9
    Medium

    CVE-2025-41076

    Last Modified: 21 Nov 2025

    In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.

    Published: 20 Nov 2025
    6.9
    Medium

    CVE-2025-41075

    Last Modified: 21 Nov 2025

    Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

    Published: 20 Nov 2025
    6.9
    Medium

    CVE-2025-41074

    Last Modified: 21 Nov 2025

    Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

    Published: 20 Nov 2025
    7.5
    High

    CVE-2025-40601

    Last Modified: 12 Dec 2025

    A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

    Published: 20 Nov 2025
    5.3
    Medium

    CVE-2025-40605

    Last Modified: 12 Dec 2025

    A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

    Published: 20 Nov 2025
    9.8
    Critical

    CVE-2025-40604

    Last Modified: 26 Feb 2026

    Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

    Published: 20 Nov 2025
    9.2
    Critical

    CVE-2025-12414

    Last Modified: 15 Apr 2026

    An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect from this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.12.100+ * 24.18.193+ * 25.0.69+ * 25.6.57+ * 25.8.39+ * 25.10.22+ * 25.12.0+

    Published: 20 Nov 2025
    7.1
    High

    CVE-2025-11676

    Last Modified: 15 Apr 2026

    Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perform DoS attack. This issue affects TL-WR940N V6 <= Build 220801.

    Published: 20 Nov 2025
    6.8
    Medium

    CVE-2025-62346

    Last Modified: 15 Apr 2026

    A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.

    Published: 20 Nov 2025
    5.1
    Medium

    CVE-2025-64984

    Last Modified: 15 Apr 2026

    Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux Nodes (any version with anti-virus databases prior to 18.11.2025), and Kaspersky Endpoint Security for Mac (12.0.0.325, 12.1.0.553, and 12.2.0.694 with anti-virus databases prior to 18.11.2025) that could have allowed a reflected XSS attack to be carried out by an attacker using phishing techniques.

    Published: 20 Nov 2025
    6.4
    Medium

    CVE-2025-5092

    Last Modified: 20 Apr 2026

    Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Nov 2025
    6.8
    Medium

    CVE-2025-12502

    Last Modified: 28 Apr 2026

    The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks

    Published: 20 Nov 2025
    5.3
    Medium

    CVE-2025-12778

    Last Modified: 21 Apr 2026

    The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial metadata of all WordPress users, including their first name, last name and email addresses.

    Published: 20 Nov 2025
    5.5
    Medium

    CVE-2025-13451

    Last Modified: 21 Nov 2025

    A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 20 Nov 2025