CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-62893

    Last Modified: 8 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 Oct 2025
    5.3
    Medium

    CVE-2025-62892

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.

    Published: 27 Oct 2025
    4.3
    Medium

    CVE-2025-62891

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows Cross Site Request Forgery.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.5.

    Published: 27 Oct 2025
    4.3
    Medium

    CVE-2025-62890

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-brands allows Cross Site Request Forgery.This issue affects Premmerce Brands for WooCommerce: from n/a through <= 1.2.13.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-62889

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-62887

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com King Addons for Elementor king-addons allows DOM-Based XSS.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

    Published: 27 Oct 2025
    7.1
    High

    CVE-2025-62886

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a through <= 1.5.3.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-62885

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.48.

    Published: 27 Oct 2025
    5.3
    Medium

    CVE-2025-62884

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.

    Published: 27 Oct 2025
    4.3
    Medium

    CVE-2025-62883

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.

    Published: 27 Oct 2025
    4.3
    Medium

    CVE-2025-62882

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

    Published: 27 Oct 2025
    4.3
    Medium

    CVE-2025-62881

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.3.

    Published: 27 Oct 2025
    2.1
    Low

    CVE-2025-12202

    Last Modified: 15 Jan 2026

    A security flaw has been discovered in ajayrandhawa User-Management-PHP-MYSQL web up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This vulnerability affects unknown code. Performing manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Oct 2025
    2
    Low

    CVE-2025-12201

    Last Modified: 15 Jan 2026

    A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part of the file /admin/edit-user.php of the component User Management Interface. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Oct 2025
    3.3
    Low

    CVE-2025-12200

    Last Modified: 3 Nov 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.

    Published: 27 Oct 2025
    3.3
    Low

    CVE-2025-12199

    Last Modified: 3 Nov 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.

    Published: 27 Oct 2025
    7.8
    High

    CVE-2025-12198

    Last Modified: 3 Nov 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of community feedback, the reported conditions represent expected and intentional behavior within dnsmasq's documented design, rather than security vulnerabilities.

    Published: 27 Oct 2025
    2.7
    Low

    CVE-2025-6601

    Last Modified: 24 Nov 2025

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-10497

    Last Modified: 28 Oct 2025

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-11971

    Last Modified: 28 Oct 2025

    GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-11974

    Last Modified: 28 Oct 2025

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to create a denial of service condition by uploading large files to specific API endpoints.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-11447

    Last Modified: 28 Oct 2025

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending GraphQL requests with crafted JSON payloads.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-52268

    Last Modified: 15 Apr 2026

    StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens.

    Published: 27 Oct 2025
    3.7
    Low

    CVE-2025-10939

    Last Modified: 15 Apr 2026

    A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.

    Published: 27 Oct 2025
    5.3
    Medium

    CVE-2023-37749

    Last Modified: 15 Apr 2026

    Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

    Published: 27 Oct 2025
    Unknown

    CVE-2025-63750

    Last Modified: 11 May 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-21709. Reason: This record is a duplicate of CVE-2026-21709. Notes: All CVE users should reference CVE-2026-21709 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 27 Oct 2025
    8.8
    High

    CVE-2023-49440

    Last Modified: 15 Apr 2026

    AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

    Published: 27 Oct 2025
    7.6
    High

    CVE-2025-60424

    Last Modified: 5 Nov 2025

    A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-61105

    Last Modified: 3 Nov 2025

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-61100

    Last Modified: 3 Nov 2025

    FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-61099

    Last Modified: 3 Nov 2025

    FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.

    Published: 27 Oct 2025
    6.1
    Medium

    CVE-2025-54965

    Last Modified: 3 Nov 2025

    An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page. An attacker who is able to social engineer a user into clicking a malicious link may be able to execute arbitrary JavaScript in the victim's browser.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-54970

    Last Modified: 31 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job owner.

    Published: 27 Oct 2025
    6.5
    Medium

    CVE-2025-54967

    Last Modified: 31 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social engineer a SOCET GXP user into opening a malicious file can trigger a variety of outbound requests, potentially compromising sensitive information in the process.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-27225

    Last Modified: 31 Oct 2025

    TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-27223

    Last Modified: 31 Oct 2025

    TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

    Published: 27 Oct 2025
    9.6
    Critical

    CVE-2025-61385

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a specially crafted Python list input to function pg8000.native.literal.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-61101

    Last Modified: 3 Nov 2025

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

    Published: 27 Oct 2025
    5.4
    Medium

    CVE-2025-60982

    Last Modified: 15 Apr 2026

    IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object references. Affected endpoints do not enforce proper authorization checks, allowing authenticated users to access or modify data belonging to other users by changing object identifiers in API requests. Attackers can exploit this flaw to view or modify sensitive records without proper authorization.

    Published: 27 Oct 2025
    8.6
    High

    CVE-2025-60425

    Last Modified: 5 Nov 2025

    Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

    Published: 27 Oct 2025
    9.1
    Critical

    CVE-2025-60291

    Last Modified: 15 Apr 2026

    An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations.

    Published: 27 Oct 2025
    6.1
    Medium

    CVE-2025-54969

    Last Modified: 31 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to submit requests to the Job Status Service without the user's knowledge.

    Published: 27 Oct 2025
    8
    High

    CVE-2025-52264

    Last Modified: 15 Apr 2026

    StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.

    Published: 27 Oct 2025
    8
    High

    CVE-2025-52263

    Last Modified: 15 Apr 2026

    An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to arbitrary code execution.

    Published: 27 Oct 2025
    8.6
    High

    CVE-2025-27222

    Last Modified: 3 Nov 2025

    TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to read any local server file that is accessible by the TRUfusion user and can also be used to leak cleartext passwords of TRUfusion Enterprise itself.

    Published: 27 Oct 2025
    8.2
    High

    CVE-2025-61247

    Last Modified: 15 Apr 2026

    indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.

    Published: 27 Oct 2025
    7.5
    High

    CVE-2025-61102

    Last Modified: 3 Nov 2025

    FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

    Published: 27 Oct 2025
    9.8
    Critical

    CVE-2025-27224

    Last Modified: 31 Oct 2025

    TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to write to any filename with any file type at any location on the local server, ultimately allowing execution of arbitrary code.

    Published: 27 Oct 2025
    8.8
    High

    CVE-2025-54968

    Last Modified: 31 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of other users.

    Published: 27 Oct 2025
    3.3
    Low

    CVE-2025-12343

    Last Modified: 26 Feb 2026

    A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.

    Published: 27 Oct 2025