CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2025-13172

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

    Published: 14 Nov 2025
    4.4
    Medium

    CVE-2025-4618

    Last Modified: 15 Apr 2026

    A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.

    Published: 14 Nov 2025
    1.1
    Low

    CVE-2025-4617

    Last Modified: 15 Apr 2026

    An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.

    Published: 14 Nov 2025
    1.1
    Low

    CVE-2025-4616

    Last Modified: 15 Apr 2026

    An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.

    Published: 14 Nov 2025
    2.1
    Low

    CVE-2025-13171

    Last Modified: 24 Feb 2026

    A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 14 Nov 2025
    7.3
    High

    CVE-2025-13204

    Last Modified: 8 Jan 2026

    npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

    Published: 14 Nov 2025
    Unknown

    CVE-2025-13197

    Last Modified: 22 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 Nov 2025
    5.5
    Medium

    CVE-2025-13170

    Last Modified: 24 Feb 2026

    A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of the argument admin_id results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

    Published: 14 Nov 2025
    5.6
    Medium

    CVE-2025-8870

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

    Published: 14 Nov 2025
    9.8
    Critical

    CVE-2025-64446

    Last Modified: 26 Feb 2026

    A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

    Published: 14 Nov 2025
    5.5
    Medium

    CVE-2025-13169

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation of the argument room_id leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

    Published: 14 Nov 2025
    2.1
    Low

    CVE-2025-13168

    Last Modified: 9 Jan 2026

    A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. Upgrading to version 0.2.1 is able to mitigate this issue. Patch name: 063384e0dddfd191847cd2d6524c342cc380b058. It is suggested to upgrade the affected component. The vendor replied and reacted very professional.

    Published: 14 Nov 2025
    7.1
    High

    CVE-2024-21635

    Last Modified: 26 Nov 2025

    Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised, they can update their password. In versions up to and including 0.18.1, though, the bad actor will still have access to their account because the bad actor's Access Token stays on the list as a valid token. The user will have to manually delete the bad actor's Access Token to secure their account. The list of Access Tokens has a generic Description which makes it hard to pinpoint a bad actor in a list of Access Tokens. A known patched version of Memos isn't available. To improve Memos security, all Access Tokens will need to be revoked when a user changes their password. This removes the session for all the user's devices and prompts the user to log in again. One can treat the old Access Tokens as "invalid" because those Access Tokens were created with the older password.

    Published: 14 Nov 2025
    6
    Medium

    CVE-2025-12149

    Last Modified: 15 Apr 2026

    In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.

    Published: 14 Nov 2025
    7.1
    High

    CVE-2025-11918

    Last Modified: 17 Nov 2025

    Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

    Published: 14 Nov 2025
    4.8
    Medium

    CVE-2025-10018

    Last Modified: 17 Nov 2025

    QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 14 Nov 2025
    6.9
    Medium

    CVE-2025-9982

    Last Modified: 17 Nov 2025

    A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 14 Nov 2025
    8.1
    High

    CVE-2025-8855

    Last Modified: 5 Jun 2026

    Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information. This issue affects Brokerage Automation: before 1.1.71.

    Published: 14 Nov 2025
    4.9
    Medium

    CVE-2025-11981

    Last Modified: 22 Apr 2026

    The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Nov 2025
    4.9
    Medium

    CVE-2025-11794

    Last Modified: 1 Dec 2025

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65071

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65072

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65066

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65067

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65068

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65069

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65070

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65064

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    Unknown

    CVE-2025-65065

    Last Modified: 15 Nov 2025

    Not used

    Published: 14 Nov 2025
    5.4
    Medium

    CVE-2025-55073

    Last Modified: 19 Nov 2025

    Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

    Published: 14 Nov 2025
    6.5
    Medium

    CVE-2025-55070

    Last Modified: 17 Nov 2025

    Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

    Published: 14 Nov 2025
    3.1
    Low

    CVE-2025-41436

    Last Modified: 17 Nov 2025

    Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2025-11776

    Last Modified: 17 Nov 2025

    Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint

    Published: 14 Nov 2025
    7.2
    High

    CVE-2025-10686

    Last Modified: 15 Apr 2026

    The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

    Published: 14 Nov 2025
    8.6
    High

    CVE-2025-64444

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.

    Published: 14 Nov 2025
    8.7
    High

    CVE-2025-13161

    Last Modified: 15 Apr 2026

    IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

    Published: 14 Nov 2025
    6.9
    Medium

    CVE-2025-13160

    Last Modified: 15 Apr 2026

    IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access specific APIs to obtain sensitive information from the internal network.

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2025-13107

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2024-7021

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2024-13178

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Nov 2025
    7.5
    High

    CVE-2024-9126

    Last Modified: 26 Feb 2026

    Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium)

    Published: 14 Nov 2025
    7.5
    High

    CVE-2024-7017

    Last Modified: 26 Feb 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2025-13102

    Last Modified: 17 Nov 2025

    Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2024-11919

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2024-11920

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 14 Nov 2025
    6.3
    Medium

    CVE-2024-13983

    Last Modified: 17 Nov 2025

    Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)

    Published: 14 Nov 2025
    4.3
    Medium

    CVE-2025-9479

    Last Modified: 17 Nov 2025

    Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Nov 2025
    5.4
    Medium

    CVE-2025-13097

    Last Modified: 17 Nov 2025

    Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 14 Nov 2025
    7.2
    High

    CVE-2025-12904

    Last Modified: 21 Apr 2026

    The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Nov 2025
    5.4
    Medium

    CVE-2025-63291

    Last Modified: 12 Jan 2026

    When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

    Published: 14 Nov 2025