CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-62264

    Last Modified: 10 Nov 2025

    Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_selectedLanguageId` parameter.

    Published: 31 Oct 2025
    4.8
    Medium

    CVE-2025-59501

    Last Modified: 22 Feb 2026

    Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

    Published: 31 Oct 2025
    1.8
    Low

    CVE-2025-6075

    Last Modified: 3 Mar 2026

    If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

    Published: 31 Oct 2025
    6.9
    Medium

    CVE-2025-12554

    Last Modified: 10 Nov 2025

    Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 31 Oct 2025
    8.4
    High

    CVE-2025-12509

    Last Modified: 15 Apr 2026

    On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.

    Published: 31 Oct 2025
    8.4
    High

    CVE-2025-12508

    Last Modified: 15 Apr 2026

    When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise confidentiality.

    Published: 31 Oct 2025
    8.8
    High

    CVE-2025-12507

    Last Modified: 15 Apr 2026

    The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.

    Published: 31 Oct 2025
    10
    Critical

    CVE-2025-12553

    Last Modified: 10 Nov 2025

    Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 31 Oct 2025
    6.9
    Medium

    CVE-2025-12552

    Last Modified: 10 Nov 2025

    Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-12357

    Last Modified: 15 Apr 2026

    By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within close proximity, via electromagnetic induction.

    Published: 31 Oct 2025
    7.1
    High

    CVE-2025-64168

    Last Modified: 15 Apr 2026

    Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to be assigned and persisted to the incorrect session. This may result in user data from one session being exposed to another user. This has been patched in version 2.2.2.

    Published: 31 Oct 2025
    9.2
    Critical

    CVE-2025-64385

    Last Modified: 15 Apr 2026

    The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Using the manufacturer's software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial configuration can be changed by means of the device's MAC without the need for authentication.

    Published: 31 Oct 2025
    8.3
    High

    CVE-2025-64389

    Last Modified: 15 Apr 2026

    The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol.

    Published: 31 Oct 2025
    9.2
    Critical

    CVE-2025-64388

    Last Modified: 15 Apr 2026

    Denial of service of the web server through specific requests to this protocol

    Published: 31 Oct 2025
    5.1
    Medium

    CVE-2025-64387

    Last Modified: 15 Apr 2026

    The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is inserted into a page controlled by the attacker in order to deceive the victim. This deception can range from making the victim click on a button to making them enter their login credentials in a form that, a priori, appears legitimate.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-12501

    Last Modified: 15 Apr 2026

    Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_create_server() function in their projects  are urged to update and recompile immediately.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-12460

    Last Modified: 15 Apr 2026

    An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img HTML tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-12521

    Last Modified: 22 Apr 2026

    The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML details. This makes it possible for unauthenticated attackers to extract usernames from source code. While we generally do not assign CVE IDs to username exposure issues, this vendor has specifically requested we consider it a vulnerability.

    Published: 31 Oct 2025
    7.7
    High

    CVE-2025-64386

    Last Modified: 15 Apr 2026

    The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal the session without the legitimate and active session detecting it. The web server allows the attacker to reuse an old session JWT token while the legitimate session is active.

    Published: 31 Oct 2025
    3.7
    Low

    CVE-2025-36249

    Last Modified: 5 Nov 2025

    IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

    Published: 31 Oct 2025
    7.8
    High

    CVE-2025-33003

    Last Modified: 26 Feb 2026

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution with unnecessary privileges.

    Published: 31 Oct 2025
    5.1
    Medium

    CVE-2024-13992

    Last Modified: 17 Nov 2025

    Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI domain.

    Published: 31 Oct 2025
    6.8
    Medium

    CVE-2025-4952

    Last Modified: 15 Apr 2026

    Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the next system startup or to unauthorized changes in the product's configuration.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-58149

    Last Modified: 14 Jan 2026

    When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the domain. For PV domains the permission leak allows the domain itself to map the memory in the page-tables. For HVM it would require a compromised device model or stubdomain to map the leaked memory into the HVM domain p2m.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-58148

    Last Modified: 14 Jan 2026

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-58147

    Last Modified: 14 Jan 2026

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of vCPU IDs as an input, in one of three formats. Xen has boundary checking bugs with all three formats, which can cause out-of-bounds reads and writes while processing the inputs. * CVE-2025-58147. Hypercalls using the HV_VP_SET Sparse format can cause vpmask_set() to write out of bounds when converting the bitmap to Xen's format. * CVE-2025-58148. Hypercalls using any input format can cause send_ipi() to read d->vcpu[] out-of-bounds, and operate on a wild vCPU pointer.

    Published: 31 Oct 2025
    5.4
    Medium

    CVE-2025-64368

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-64367

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groundhogg groundhogg allows Stored XSS.This issue affects Groundhogg: from n/a through <= 4.2.6.

    Published: 31 Oct 2025
    7.6
    High

    CVE-2025-64366

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.6.27.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-64365

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extra ohio-extra allows DOM-Based XSS.This issue affects Ohio Extra: from n/a through <= 3.6.0.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-64364

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue affects Masterstudy: from n/a through < 4.8.126.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-64363

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeventhQueen Kleo kleo allows PHP Local File Inclusion.This issue affects Kleo: from n/a through < 5.5.0.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-64362

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Elements k-elements allows DOM-Based XSS.This issue affects K Elements: from n/a through < 5.5.0.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-64361

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-64360

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-64359

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-64358

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from n/a through <= 2.2.3.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-64357

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <= 3.1.6.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-64356

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from n/a through <= 1.4.3.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-64354

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2.

    Published: 31 Oct 2025
    8.8
    High

    CVE-2025-64353

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.

    Published: 31 Oct 2025
    2.7
    Low

    CVE-2025-64352

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-64351

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

    Published: 31 Oct 2025
    3.8
    Low

    CVE-2025-64350

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

    Published: 31 Oct 2025
    4.5
    Medium

    CVE-2025-40603

    Last Modified: 6 Nov 2025

    A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.

    Published: 31 Oct 2025
    6.3
    Medium

    CVE-2025-11602

    Last Modified: 15 Apr 2026

    Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.

    Published: 31 Oct 2025
    8.8
    High

    CVE-2025-11843

    Last Modified: 15 Apr 2026

    Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore™ Server. If the malicious user gains this impersonation user access, then it is possible for them to access the documents stored in Therefore™. This impersonation is at application level (Therefore access level), not the operating system level.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-12115

    Last Modified: 21 Apr 2026

    The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-12041

    Last Modified: 15 Apr 2026

    The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download files restricted to specific user roles.

    Published: 31 Oct 2025
    7.4
    High

    CVE-2025-30189

    Last Modified: 15 Apr 2026

    When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

    Published: 31 Oct 2025