CVE Feed

    Dashboard / CVE

    8.9
    High

    CVE-2025-64163

    Last Modified: 7 Nov 2025

    DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in an SSRF vulnerability. This issue is fixed in version 2.10.15.

    Published: 5 Nov 2025
    6.5
    Medium

    CVE-2025-64114

    Last Modified: 24 Nov 2025

    ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management privileges to execute arbitrary SQL commands against the database through its ClipBucket Custom Fields plugin. The vulnerabilities require the Custom Fields plugin to be installed and accessible, and can only be exploited by users with administrative access to the plugin interface. This issue is fixed in version 5.5.2 - #.

    Published: 5 Nov 2025
    7.3
    High

    CVE-2025-62596

    Last Modified: 10 Nov 2025

    Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with path substitution during pathname resolution, can allow writes to unintended procfs locations. While resolving a path component-by-component, a shared-mount race can substitute intermediate components and redirect the final target. This issue is fixed in version 0.5.7.

    Published: 5 Nov 2025
    7.3
    High

    CVE-2025-62161

    Last Modified: 10 Nov 2025

    Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask. This issue is fixed in version 0.5.7.

    Published: 5 Nov 2025
    8.1
    High

    CVE-2025-55278

    Last Modified: 15 Apr 2026

    Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their expiration and cryptographic signature. As a result, an attacker could potentially use expired or tampered tokens to gain unauthorized access to sensitive resources and perform actions with elevated privileges.

    Published: 5 Nov 2025
    Unknown

    CVE-2025-12780

    Last Modified: 23 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Nov 2025
    8.8
    High

    CVE-2025-12779

    Last Modified: 15 Apr 2026

    Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's authentication token from the shared client machine and access their WorkSpace. To mitigate this issue, users should upgrade to the Amazon WorkSpaces client for Linux version 2025.0 or later.

    Published: 5 Nov 2025
    5.2
    Medium

    CVE-2025-10853

    Last Modified: 13 Nov 2025

    A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in UI manipulation, redirection to malicious websites, or data theft from the browser. However, session-related sensitive cookies are protected with the httpOnly flag, which mitigates the risk of session hijacking.

    Published: 5 Nov 2025
    6.1
    Medium

    CVE-2025-5770

    Last Modified: 13 Nov 2025

    A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks. Exploitation may result in redirection to malicious websites, UI manipulation, or unauthorized data access from the victim’s browser. However, session-related cookies are protected with the httpOnly flag, which mitigates session hijacking via this vector.

    Published: 5 Nov 2025
    4.6
    Medium

    CVE-2025-43418

    Last Modified: 27 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

    Published: 5 Nov 2025
    8.8
    High

    CVE-2023-43000

    Last Modified: 12 Mar 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

    Published: 5 Nov 2025
    1.9
    Low

    CVE-2025-12745

    Last Modified: 8 Jan 2026

    A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be exploited. This product adopts a rolling release strategy to maintain continuous delivery Patch name: c6fe5a98fd3ef3b7064e6e0145dfebfe12449fea. To fix this issue, it is recommended to deploy a patch.

    Published: 5 Nov 2025
    8.4
    High

    CVE-2025-11093

    Last Modified: 9 Jan 2026

    An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting engines is limited to administrators in WSO2 Micro Integrator and WSO2 Enterprise Integrator, while in WSO2 API Manager, access extends to both administrators and API creators. This may allow trusted-but-privileged users to perform unauthorized actions or compromise the execution environment.

    Published: 5 Nov 2025
    5.4
    Medium

    CVE-2025-31954

    Last Modified: 7 Nov 2025

    HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.

    Published: 5 Nov 2025
    8.4
    High

    CVE-2025-10907

    Last Modified: 4 Dec 2025

    An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful exploitation may lead to remote code execution (RCE) on the server, depending on how the uploaded file is processed. By default, this vulnerability is only exploitable by users with administrative access to the affected SOAP services.

    Published: 5 Nov 2025
    6.5
    Medium

    CVE-2025-10713

    Last Modified: 4 Dec 2025

    An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server's filesystem or perform denial-of-service (DoS) attacks that render affected services unavailable.

    Published: 5 Nov 2025
    7.3
    High

    CVE-2025-43990

    Last Modified: 26 Feb 2026

    Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 5 Nov 2025
    6.7
    Medium

    CVE-2025-46366

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information.

    Published: 5 Nov 2025
    6.7
    Medium

    CVE-2025-46424

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service.

    Published: 5 Nov 2025
    5.3
    Medium

    CVE-2025-46365

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink.

    Published: 5 Nov 2025
    9.1
    Critical

    CVE-2025-46364

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system.

    Published: 5 Nov 2025
    5.4
    Medium

    CVE-2025-20304

    Last Modified: 4 Dec 2025

    Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have at least a low-privileged account on the affected device.

    Published: 5 Nov 2025
    Unknown

    CVE-2025-12759

    Last Modified: 23 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Nov 2025
    4.3
    Medium

    CVE-2025-20305

    Last Modified: 4 Dec 2025

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could exploit this vulnerability by performing actions where the results should only be viewable to a high-privileged user. A successful exploit could allow the attacker to view passwords that are normally not visible to read-only administrators.

    Published: 5 Nov 2025
    4.8
    Medium

    CVE-2025-20289

    Last Modified: 4 Dec 2025

    Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have at least a low-privileged account on the affected device.

    Published: 5 Nov 2025
    5.4
    Medium

    CVE-2025-20303

    Last Modified: 4 Dec 2025

    Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have at least a low-privileged account on the affected device.

    Published: 5 Nov 2025
    8.4
    High

    CVE-2025-45379

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system.

    Published: 5 Nov 2025
    4.3
    Medium

    CVE-2025-20377

    Last Modified: 15 Apr 2026

    A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive information on the affected system that should be restricted. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

    Published: 5 Nov 2025
    6.5
    Medium

    CVE-2025-20375

    Last Modified: 26 Feb 2026

    A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by uploading a crafted file to the web UI. A successful exploit could allow the attacker to upload arbitrary files to a vulnerable system and execute them, gaining access to the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.

    Published: 5 Nov 2025
    6.5
    Medium

    CVE-2025-20376

    Last Modified: 26 Feb 2026

    A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exploit this vulnerability by uploading a malicious file to the web UI and executing it. A successful exploit could allow the attacker to execute arbitrary commands on the underlying system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

    Published: 5 Nov 2025
    4.9
    Medium

    CVE-2025-20374

    Last Modified: 17 Nov 2025

    A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to arbitrary files on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.

    Published: 5 Nov 2025
    9.4
    Critical

    CVE-2025-20358

    Last Modified: 26 Feb 2026

    A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.

    Published: 5 Nov 2025
    9.8
    Critical

    CVE-2025-20354

    Last Modified: 26 Feb 2026

    A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.

    Published: 5 Nov 2025
    8.6
    High

    CVE-2025-20343

    Last Modified: 19 Nov 2025

    A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejected endpoint. An attacker could exploit this vulnerability by sending a specific sequence of multiple crafted RADIUS access request messages to Cisco ISE. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when Cisco ISE restarts.

    Published: 5 Nov 2025
    8.4
    High

    CVE-2025-30479

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

    Published: 5 Nov 2025
    9.1
    Critical

    CVE-2025-45378

    Last Modified: 26 Feb 2026

    Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is possible through network with known privileged user/password.

    Published: 5 Nov 2025
    9.1
    Critical

    CVE-2025-64459

    Last Modified: 26 Feb 2026

    An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.

    Published: 5 Nov 2025
    7.5
    High

    CVE-2025-64458

    Last Modified: 10 Nov 2025

    An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and the shortcut `django.shortcuts.redirect` were subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Seokchan Yoon for reporting this issue.

    Published: 5 Nov 2025
    9.8
    Critical

    CVE-2025-47151

    Last Modified: 7 Nov 2025

    A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.

    Published: 5 Nov 2025
    7.5
    High

    CVE-2025-46404

    Last Modified: 7 Nov 2025

    A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.

    Published: 5 Nov 2025
    7.5
    High

    CVE-2025-46784

    Last Modified: 7 Nov 2025

    A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.

    Published: 5 Nov 2025
    7.5
    High

    CVE-2025-46705

    Last Modified: 7 Nov 2025

    A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.

    Published: 5 Nov 2025
    6.7
    Medium

    CVE-2025-3125

    Last Modified: 20 Jan 2026

    An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code execution (RCE). This functionality is restricted by default to admin users; therefore, successful exploitation requires valid credentials with administrative permissions.

    Published: 5 Nov 2025
    4.2
    Medium

    CVE-2025-52602

    Last Modified: 15 Apr 2026

    HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint request returns discoverable responses that may disclose: group names, active user names (or IDs).  An attacker can use that information to target individuals with phishing or other social-engineering attacks.

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64475

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64476

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64477

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64478

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64479

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025
    Unknown

    CVE-2025-64480

    Last Modified: 6 Nov 2025

    Not used

    Published: 5 Nov 2025