CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-30191

    Last Modified: 15 Apr 2026

    Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure. No publicly available exploits are known

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-30188

    Last Modified: 15 Apr 2026

    Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No publicly available exploits are known

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-62232

    Last Modified: 5 Nov 2025

    Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-8383

    Last Modified: 20 Apr 2026

    The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-12094

    Last Modified: 21 Apr 2026

    The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1.2.53. This is due to the plugin trusting client-controlled forwarded headers (such as CF-Connecting-IP, X-Forwarded-For, and others) without verifying that those headers originate from legitimate, trusted proxies. This makes it possible for unauthenticated attackers to spoof their IP address and bypass IP-based security controls, including blocked IP lists and rate limiting protections, by sending arbitrary HTTP headers with their requests.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-12175

    Last Modified: 21 Apr 2026

    The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event names and generate/view QR codes for them.

    Published: 31 Oct 2025
    9.8
    Critical

    CVE-2025-6520

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection. This issue affects BAPSIS: before 202510271606.

    Published: 31 Oct 2025
    6.8
    Medium

    CVE-2025-8385

    Last Modified: 20 Apr 2026

    The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation in the zf_get_file_by_url function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrary files on the server, including sensitive system files like /etc/passwd, via a forged request. It's worth noting that successfully exploiting this vulnerability relies on a race condition as the file generated will be deleted immediately.

    Published: 31 Oct 2025
    8.6
    High

    CVE-2025-10897

    Last Modified: 22 Apr 2026

    The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.

    Published: 31 Oct 2025
    8.8
    High

    CVE-2025-7846

    Last Modified: 20 Apr 2026

    The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 31 Oct 2025
    9.8
    Critical

    CVE-2025-8489

    Last Modified: 15 Apr 2026

    The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

    Published: 31 Oct 2025
    9.8
    Critical

    CVE-2025-5397

    Last Modified: 21 Apr 2026

    The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard authentication and access administrative user accounts. Please note social login needs to be enabled in order for a site to be impacted by this vulnerability.

    Published: 31 Oct 2025
    5.3
    Medium

    CVE-2025-11191

    Last Modified: 15 Apr 2026

    The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

    Published: 31 Oct 2025
    8.6
    High

    CVE-2025-54763

    Last Modified: 15 Apr 2026

    FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.

    Published: 31 Oct 2025
    6.9
    Medium

    CVE-2025-58152

    Last Modified: 15 Apr 2026

    FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.

    Published: 31 Oct 2025
    6.4
    Medium

    CVE-2025-11806

    Last Modified: 21 Apr 2026

    The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'quiz' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Oct 2025
    4.3
    Medium

    CVE-2025-11975

    Last Modified: 22 Apr 2026

    The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1.23.0. This makes it possible for unauthenticated attackers to add and edit sync rules.

    Published: 31 Oct 2025
    Unknown

    CVE-2025-12542

    Last Modified: 10 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-6176

    Last Modified: 15 Apr 2026

    Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.

    Published: 31 Oct 2025
    5.5
    Medium

    CVE-2025-40106

    Last Modified: 15 Apr 2026

    In the Linux kernel, the following vulnerability has been resolved: comedi: fix divide-by-zero in comedi_buf_munge() The comedi_buf_munge() function performs a modulo operation `async->munge_chan %= async->cmd.chanlist_len` without first checking if chanlist_len is zero. If a user program submits a command with chanlist_len set to zero, this causes a divide-by-zero error when the device processes data in the interrupt handler path. Add a check for zero chanlist_len at the beginning of the function, similar to the existing checks for !map and CMDF_RAWDATA flag. When chanlist_len is zero, update munge_count and return early, indicating the data was handled without munging. This prevents potential kernel panics from malformed user commands.

    Published: 31 Oct 2025
    6.9
    Medium

    CVE-2025-63675

    Last Modified: 8 Dec 2025

    cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63460

    Last Modified: 5 Nov 2025

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63454

    Last Modified: 5 Nov 2025

    Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    6.5
    Medium

    CVE-2025-63563

    Last Modified: 5 Nov 2025

    Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63465

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63458

    Last Modified: 5 Nov 2025

    Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    6.1
    Medium

    CVE-2025-61427

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the userid and password parameters.

    Published: 31 Oct 2025
    3.1
    Low

    CVE-2025-23050

    Last Modified: 15 Apr 2026

    QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.

    Published: 31 Oct 2025
    6.3
    Medium

    CVE-2025-63562

    Last Modified: 5 Nov 2025

    Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63561

    Last Modified: 5 Nov 2025

    Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s connection pool and worker capacity, preventing legitimate users and APIs from accessing the service.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63463

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63461

    Last Modified: 5 Nov 2025

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63467

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63466

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63464

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63459

    Last Modified: 5 Nov 2025

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.1
    High

    CVE-2025-57107

    Last Modified: 5 Nov 2025

    Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.

    Published: 31 Oct 2025
    9.8
    Critical

    CVE-2025-57108

    Last Modified: 5 Nov 2025

    Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63462

    Last Modified: 5 Nov 2025

    Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63468

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-57106

    Last Modified: 5 Nov 2025

    Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-63469

    Last Modified: 5 Nov 2025

    Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

    Published: 31 Oct 2025
    10
    Critical

    CVE-2025-29270

    Last Modified: 15 Apr 2026

    Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.

    Published: 31 Oct 2025
    7.8
    High

    CVE-2025-60749

    Last Modified: 15 Apr 2026

    DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

    Published: 31 Oct 2025
    7.5
    High

    CVE-2025-8849

    Last Modified: 10 Nov 2025

    LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

    Published: 30 Oct 2025
    Unknown

    CVE-2025-12541

    Last Modified: 22 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Oct 2025
    9.9
    Critical

    CVE-2025-48983

    Last Modified: 26 Feb 2026

    A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

    Published: 30 Oct 2025
    7.8
    High

    CVE-2025-48982

    Last Modified: 26 Feb 2026

    This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

    Published: 30 Oct 2025
    6.1
    Medium

    CVE-2025-27208

    Last Modified: 1 Dec 2025

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.

    Published: 30 Oct 2025
    8.8
    High

    CVE-2025-48984

    Last Modified: 26 Feb 2026

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

    Published: 30 Oct 2025