CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-36091

    Last Modified: 5 Nov 2025

    IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.

    Published: 3 Nov 2025
    8.5
    High

    CVE-2025-11761

    Last Modified: 26 Feb 2026

    A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability.

    Published: 3 Nov 2025
    9.8
    Critical

    CVE-2025-8900

    Last Modified: 22 Apr 2026

    The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_type' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.

    Published: 3 Nov 2025
    5.3
    Medium

    CVE-2025-64294

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through <= 1.1.19.

    Published: 3 Nov 2025
    2.1
    Low

    CVE-2025-12626

    Last Modified: 15 Apr 2026

    A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the argument imgurl results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The root cause was initially fixed but can be evaded with additional encoding.

    Published: 3 Nov 2025
    9.9
    Critical

    CVE-2025-0987

    Last Modified: 6 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Nov 2025
    7.1
    High

    CVE-2025-48397

    Last Modified: 15 Apr 2026

    The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

    Published: 3 Nov 2025
    1.3
    Low

    CVE-2025-12623

    Last Modified: 15 Apr 2026

    A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component Authentication Token Handler. Such manipulation leads to authorization bypass. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.

    Published: 3 Nov 2025
    8.3
    High

    CVE-2025-48396

    Last Modified: 15 Apr 2026

    Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

    Published: 3 Nov 2025
    7.4
    High

    CVE-2025-12622

    Last Modified: 24 Feb 2026

    A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 3 Nov 2025
    7.4
    High

    CVE-2025-12619

    Last Modified: 24 Feb 2026

    A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 3 Nov 2025
    7.1
    High

    CVE-2025-12503

    Last Modified: 15 Apr 2026

    EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

    Published: 3 Nov 2025
    7.4
    High

    CVE-2025-12618

    Last Modified: 24 Feb 2026

    A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Nov 2025
    5.5
    Medium

    CVE-2025-12617

    Last Modified: 24 Feb 2026

    A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 3 Nov 2025
    2.9
    Low

    CVE-2025-12616

    Last Modified: 24 Feb 2026

    A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.

    Published: 3 Nov 2025
    1.3
    Low

    CVE-2025-12615

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.

    Published: 3 Nov 2025
    2
    Low

    CVE-2025-12614

    Last Modified: 5 Nov 2025

    A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

    Published: 3 Nov 2025
    2.1
    Low

    CVE-2025-12612

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

    Published: 3 Nov 2025
    7.4
    High

    CVE-2025-12611

    Last Modified: 24 Feb 2026

    A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

    Published: 3 Nov 2025
    2
    Low

    CVE-2025-12610

    Last Modified: 24 Feb 2026

    A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 3 Nov 2025
    2
    Low

    CVE-2025-12609

    Last Modified: 24 Feb 2026

    A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation of the argument id/ini_weight results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.

    Published: 3 Nov 2025
    5.5
    Medium

    CVE-2025-12608

    Last Modified: 5 Nov 2025

    A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.

    Published: 3 Nov 2025
    5.5
    Medium

    CVE-2025-12607

    Last Modified: 5 Nov 2025

    A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 3 Nov 2025
    5.5
    Medium

    CVE-2025-40107

    Last Modified: 15 Apr 2026

    In the Linux kernel, the following vulnerability has been resolved: can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled This issue is similar to the vulnerability in the `mcp251x` driver, which was fixed in commit 03c427147b2d ("can: mcp251x: fix resume from sleep before interface was brought up"). In the `hi311x` driver, when the device resumes from sleep, the driver schedules `priv->restart_work`. However, if the network interface was not previously enabled, the `priv->wq` (workqueue) is not allocated and initialized, leading to a null pointer dereference. To fix this, we move the allocation and initialization of the workqueue from the `hi3110_open` function to the `hi3110_can_probe` function. This ensures that the workqueue is properly initialized before it is used during device resume. And added logic to destroy the workqueue in the error handling paths of `hi3110_can_probe` and in the `hi3110_can_remove` function to prevent resource leaks.

    Published: 3 Nov 2025
    7.5
    High

    CVE-2024-12125

    Last Modified: 15 Apr 2026

    A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.

    Published: 3 Nov 2025
    6.1
    Medium

    CVE-2025-63446

    Last Modified: 10 Nov 2025

    Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.

    Published: 3 Nov 2025
    5.4
    Medium

    CVE-2025-63450

    Last Modified: 7 Nov 2025

    Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.

    Published: 3 Nov 2025
    6.1
    Medium

    CVE-2025-63447

    Last Modified: 7 Nov 2025

    Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.

    Published: 3 Nov 2025
    6.1
    Medium

    CVE-2025-63593

    Last Modified: 7 Nov 2025

    Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

    Published: 3 Nov 2025
    7.5
    High

    CVE-2025-50735

    Last Modified: 5 Nov 2025

    Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.

    Published: 3 Nov 2025
    5.4
    Medium

    CVE-2025-50363

    Last Modified: 5 Nov 2025

    Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

    Published: 3 Nov 2025
    6.5
    Medium

    CVE-2025-45663

    Last Modified: 5 Nov 2025

    An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

    Published: 3 Nov 2025
    8.7
    High

    CVE-2025-60503

    Last Modified: 3 Feb 2026

    A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

    Published: 3 Nov 2025
    9.4
    Critical

    CVE-2025-63452

    Last Modified: 7 Nov 2025

    Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

    Published: 3 Nov 2025
    9.8
    Critical

    CVE-2025-63451

    Last Modified: 7 Nov 2025

    Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

    Published: 3 Nov 2025
    6.1
    Medium

    CVE-2025-63448

    Last Modified: 10 Nov 2025

    Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.

    Published: 3 Nov 2025
    7.3
    High

    CVE-2025-63441

    Last Modified: 4 Feb 2026

    Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

    Published: 3 Nov 2025
    6.5
    Medium

    CVE-2025-63293

    Last Modified: 14 Nov 2025

    FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.

    Published: 3 Nov 2025
    6.5
    Medium

    CVE-2025-29699

    Last Modified: 5 Nov 2025

    NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

    Published: 3 Nov 2025
    4.6
    Medium

    CVE-2025-63442

    Last Modified: 5 Nov 2025

    Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, allowing attackers to inject and execute arbitrary JavaScript when the input is displayed in the browser

    Published: 3 Nov 2025
    5.4
    Medium

    CVE-2025-63443

    Last Modified: 3 Feb 2026

    School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

    Published: 3 Nov 2025
    5.4
    Medium

    CVE-2025-63449

    Last Modified: 7 Nov 2025

    Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.

    Published: 3 Nov 2025
    9.8
    Critical

    CVE-2025-63453

    Last Modified: 7 Nov 2025

    Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.

    Published: 3 Nov 2025
    6.5
    Medium

    CVE-2024-51317

    Last Modified: 5 Nov 2025

    An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

    Published: 3 Nov 2025
    8.8
    High

    CVE-2025-60785

    Last Modified: 4 Feb 2026

    A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted HTML page.

    Published: 3 Nov 2025
    6.8
    Medium

    CVE-2025-60892

    Last Modified: 15 Apr 2026

    An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it could allow an attacker to use a different key than the intended one to login to the device.

    Published: 3 Nov 2025
    5.5
    Medium

    CVE-2025-12606

    Last Modified: 5 Nov 2025

    A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

    Published: 2 Nov 2025
    5.5
    Medium

    CVE-2025-12605

    Last Modified: 5 Nov 2025

    A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 2 Nov 2025
    5.5
    Medium

    CVE-2025-12604

    Last Modified: 5 Nov 2025

    A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Nov 2025
    2
    Low

    CVE-2025-12598

    Last Modified: 5 Nov 2025

    A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argument firstname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.

    Published: 2 Nov 2025