CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2025-61945

    Last Modified: 12 Nov 2025

    Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and flight safety. This unauthorized access could result in the disabling of vital alerts, causing hazardous conditions for aircraft, and manipulating runway assignments, which could result in mid-air conflicts or runway incursions.

    Published: 4 Nov 2025
    Unknown

    CVE-2025-12700

    Last Modified: 20 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64449

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64450

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64451

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64452

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64453

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64454

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64455

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    Unknown

    CVE-2025-64448

    Last Modified: 5 Nov 2025

    Not used

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-12184

    Last Modified: 22 Apr 2026

    The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-12682

    Last Modified: 22 Apr 2026

    The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files on the affected site's server which may make remote code execution possible.

    Published: 4 Nov 2025
    5.9
    Medium

    CVE-2025-12695

    Last Modified: 15 Apr 2026

    The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41345

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDenunciasById.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41344

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api/verArchivo.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41343

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/users/searchUserByEmail.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41342

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/buscarUsuarioId.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41341

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41340

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_sociedad' in '/backend/api/buscarTipoDenunciabyId.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41339

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41338

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41337

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41336

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41335

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41114

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41113

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41112

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'.

    Published: 4 Nov 2025
    8.7
    High

    CVE-2025-41111

    Last Modified: 5 Nov 2025

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.

    Published: 4 Nov 2025
    6.4
    Medium

    CVE-2025-12045

    Last Modified: 15 Apr 2026

    The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the category and tag 'name' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-12493

    Last Modified: 22 Apr 2026

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

    Published: 4 Nov 2025
    8.5
    High

    CVE-2025-11690

    Last Modified: 15 Apr 2026

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. The fix for this vulnerability is a server-side authorization fix.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20749

    Last Modified: 26 Feb 2026

    In charger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09915493; Issue ID: MSV-3800.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20748

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432679; Issue ID: MSV-3950.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20741

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20747

    Last Modified: 26 Feb 2026

    In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20746

    Last Modified: 26 Feb 2026

    In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20739

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20738

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435342; Issue ID: MSV-4039.

    Published: 4 Nov 2025
    6.7
    Medium

    CVE-2025-20736

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435347; Issue ID: MSV-4049.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-20734

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00441507; Issue ID: MSV-4112.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-20732

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441510; Issue ID: MSV-4139.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-20731

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441511; Issue ID: MSV-4140.

    Published: 4 Nov 2025
    4.2
    Medium

    CVE-2025-20729

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00441512; Issue ID: MSV-4153.

    Published: 4 Nov 2025
    4.2
    Medium

    CVE-2025-20745

    Last Modified: 26 Feb 2026

    In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10095441; Issue ID: MSV-4294.

    Published: 4 Nov 2025
    4.2
    Medium

    CVE-2025-20744

    Last Modified: 26 Feb 2026

    In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10127160; Issue ID: MSV-4542.

    Published: 4 Nov 2025
    4.2
    Medium

    CVE-2025-20743

    Last Modified: 26 Feb 2026

    In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10136671; Issue ID: MSV-4651.

    Published: 4 Nov 2025
    8
    High

    CVE-2025-20742

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949.

    Published: 4 Nov 2025
    4.7
    Medium

    CVE-2025-20740

    Last Modified: 5 Nov 2025

    In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-20737

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-20735

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435349; Issue ID: MSV-4051.

    Published: 4 Nov 2025