CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-61430

    Last Modified: 15 Apr 2026

    Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server to return request payloads from other clients. This happens when the TCP length prefix is malformed (len differs from actual packet len), and due to a concurrency/buffering issue, even when the lengths match. A length prefix that is smaller than the actual packet size increases information leakage. In summary, this vulnerability allows an attacker to see DNS queries of other clients.

    Published: 24 Oct 2025
    6.4
    Medium

    CVE-2025-7730

    Last Modified: 21 Apr 2026

    The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Oct 2025
    6.3
    Medium

    CVE-2025-60023

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine.

    Published: 23 Oct 2025
    6.3
    Medium

    CVE-2025-59776

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary directories on the target machine.

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-62254

    Last Modified: 10 Nov 2025

    The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or size of the files it will combine, which allows remote attackers to create very large responses that lead to a denial of service attack via the URL query string.

    Published: 23 Oct 2025
    8.3
    High

    CVE-2025-58429

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary files on the target machine.

    Published: 23 Oct 2025
    8.3
    High

    CVE-2025-58078

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and write files with arbitrary data on the target machine.

    Published: 23 Oct 2025
    8.2
    High

    CVE-2025-58456

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.

    Published: 23 Oct 2025
    9.3
    Critical

    CVE-2025-61934

    Last Modified: 15 Apr 2026

    A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-62688

    Last Modified: 15 Apr 2026

    An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.

    Published: 23 Oct 2025
    7.3
    High

    CVE-2025-61977

    Last Modified: 15 Apr 2026

    A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.

    Published: 23 Oct 2025
    8.6
    High

    CVE-2025-62498

    Last Modified: 15 Apr 2026

    A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine where the project is opened.

    Published: 23 Oct 2025
    10
    Critical

    CVE-2025-59503

    Last Modified: 26 Feb 2026

    Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

    Published: 23 Oct 2025
    7.3
    High

    CVE-2025-59273

    Last Modified: 26 Feb 2026

    Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

    Published: 23 Oct 2025
    7.7
    High

    CVE-2025-59500

    Last Modified: 26 Feb 2026

    Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

    Published: 23 Oct 2025
    8.8
    High

    CVE-2025-12100

    Last Modified: 15 Apr 2026

    Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.

    Published: 23 Oct 2025
    6.4
    Medium

    CVE-2025-57848

    Last Modified: 6 Aug 2026

    A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

    Published: 23 Oct 2025
    5.9
    Medium

    CVE-2025-62517

    Last Modified: 15 Apr 2026

    Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input.

    Published: 23 Oct 2025
    9.4
    Critical

    CVE-2025-58428

    Last Modified: 15 Apr 2026

    The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.

    Published: 23 Oct 2025
    7.1
    High

    CVE-2025-55067

    Last Modified: 15 Apr 2026

    The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as login access, history visibility, and leak detection termination. This vulnerability could allow an attacker to manipulate the system time to trigger a denial of service (DoS) condition, leading to administrative lockout, operational timer failures, and corrupted log entries.

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-62236

    Last Modified: 31 Dec 2025

    The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.

    Published: 23 Oct 2025
    7.5
    High

    CVE-2025-12044

    Last Modified: 23 Dec 2025

    Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393]  which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.

    Published: 23 Oct 2025
    8.1
    High

    CVE-2025-11621

    Last Modified: 26 Feb 2026

    Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27

    Published: 23 Oct 2025
    7.2
    High

    CVE-2025-6978

    Last Modified: 15 Apr 2026

    Diagnostics command injection vulnerability

    Published: 23 Oct 2025
    2
    Low

    CVE-2025-62255

    Last Modified: 12 Dec 2025

    Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an attachment's filename.

    Published: 23 Oct 2025
    8.8
    High

    CVE-2025-6979

    Last Modified: 15 Apr 2026

    Captive Portal can allow authentication bypass

    Published: 23 Oct 2025
    7.5
    High

    CVE-2025-6980

    Last Modified: 15 Apr 2026

    Captive Portal can expose sensitive information

    Published: 23 Oct 2025
    7.8
    High

    CVE-2025-23352

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitialized pointer access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 23 Oct 2025
    Unknown

    CVE-2025-12127

    Last Modified: 10 Jul 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 Oct 2025
    7.8
    High

    CVE-2025-23347

    Last Modified: 15 Apr 2026

    NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

    Published: 23 Oct 2025
    4.4
    Medium

    CVE-2025-23345

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

    Published: 23 Oct 2025
    5
    Medium

    CVE-2025-23332

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

    Published: 23 Oct 2025
    5.5
    Medium

    CVE-2025-23330

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

    Published: 23 Oct 2025
    6.8
    Medium

    CVE-2025-10937

    Last Modified: 15 Apr 2026

    Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying it to its final location. This temporary file is created in a directory accessible to all users on the system. An unauthorized local user or process can exploit this behavior by placing a file lock on the temporary token file using the flock system call. This prevents MinKNOW from completing the token generation process. As a result, no valid local token is created, and the software is unable to execute commands on the sequencer. This leads to a denial-of-service (DoS) condition, blocking sequencing operations.

    Published: 23 Oct 2025
    5.5
    Medium

    CVE-2025-23300

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.

    Published: 23 Oct 2025
    7.3
    High

    CVE-2025-54808

    Last Modified: 4 Jun 2026

    Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access the token. If the token is leaked (e.g., via malware infection or other local exploit), and remote access is enabled, it can be used to establish unauthorized remote connections to the sequencer. Remote access must be enabled for remote exploitation to succeed. This may occur either because the user has enabled remote access for legitimate operational reasons or because malware with elevated privileges (e.g., sudo access) enables it without user consent. This vulnerability can be chained with remote access capabilities to generate a developer token from a remote device. Developer tokens can be created with arbitrary expiration dates, enabling persistent access to the sequencer and bypassing standard authentication mechanisms.

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-34156

    Last Modified: 14 May 2026

    Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-34155

    Last Modified: 14 May 2026

    Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote attacker to infer valid account identifiers. This can facilitate user enumeration and increase the likelihood of targeted brute-force or credential-stuffing attacks.

    Published: 23 Oct 2025
    7.2
    High

    CVE-2025-62713

    Last Modified: 15 Apr 2026

    Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected. This issue has been fixed in version 3.3.2.

    Published: 23 Oct 2025
    8.1
    High

    CVE-2025-62169

    Last Modified: 15 Apr 2026

    OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. This issue has been patched in versions 1.8.0a3 of the testing branch and 1.7.8 of the stable branch. The impact of this vulnerability is greatly reduced when using OctoPrint version 1.11.2 and newer.

    Published: 23 Oct 2025
    5.2
    Medium

    CVE-2025-12114

    Last Modified: 10 Nov 2025

    Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 23 Oct 2025
    8.1
    High

    CVE-2025-59048

    Last Modified: 5 Dec 2025

    OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation in the AWS auth method. The vulnerability allows an IAM role from an untrusted AWS account to authenticate by impersonating a role with the same name in a trusted account, leading to unauthorized access. This impacts all users of the auth-aws plugin who operate in a multi-account AWS environment where IAM role names may not be unique across accounts. This vulnerability has been patched in version 0.1.1 of the auth-aws plugin. A workaround for this issue involves guaranteeing that IAM role names are unique across all AWS accounts that could potentially interact with your OpenBao environment, and to audit for any duplicate IAM roles.

    Published: 23 Oct 2025
    0
    Low

    CVE-2025-1680

    Last Modified: 15 Apr 2026

    An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service. This vulnerability is classified as Host Header Injection, where invalid Host headers can manipulate to redirect users, forge links, or phishing attacks. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of confidentiality, integrity, and availability within any subsequent systems.

    Published: 23 Oct 2025
    4.8
    Medium

    CVE-2025-1679

    Last Modified: 15 Apr 2026

    Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored cross-site scripting (XSS); attackers inject malicious scripts into the system, and the scripts persist across sessions. There is no impact to the confidentiality, integrity, and availability of the affected device; no loss of availability within any subsequent systems but has some loss of confidentiality and integrity within the subsequent system.

    Published: 23 Oct 2025
    6.9
    Medium

    CVE-2025-62256

    Last Modified: 10 Nov 2025

    Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

    Published: 23 Oct 2025
    4.8
    Medium

    CVE-2025-53701

    Last Modified: 4 Nov 2025

    Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, making it possible to target logged in admin users. The vendor did not respond in any way. Only version 1.1.0.18 was tested, other versions might be vulnerable as well.

    Published: 23 Oct 2025
    7.1
    High

    CVE-2025-53702

    Last Modified: 4 Nov 2025

    Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A manual restart of the device is required.  The vendor did not respond in any way. Only version 1.1.0.18 was tested, other versions might be vulnerable as well.

    Published: 23 Oct 2025
    5.3
    Medium

    CVE-2025-10705

    Last Modified: 21 Apr 2026

    The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. This is due to insufficient validation of user-supplied URLs in the PDF processing functionality. This makes it possible for unauthenticated attackers to make the WordPress server perform HTTP requests to arbitrary destinations via the mxchat_handle_chat_request AJAX action.

    Published: 23 Oct 2025
    5
    Medium

    CVE-2025-11128

    Last Modified: 21 Apr 2026

    The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query information from internal services.

    Published: 23 Oct 2025
    6.4
    Medium

    CVE-2025-8427

    Last Modified: 20 Apr 2026

    The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Oct 2025