CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-11023

    Last Modified: 4 Jun 2026

    Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows PHP Local File Inclusion. This issue affects AcBakImzala: before v5.1.4.

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62835

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62827

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62828

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62829

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62830

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62831

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62832

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62833

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    Unknown

    CVE-2025-62834

    Last Modified: 24 Oct 2025

    Not used

    Published: 23 Oct 2025
    5.4
    Medium

    CVE-2025-62401

    Last Modified: 14 Nov 2025

    An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

    Published: 23 Oct 2025
    4.3
    Medium

    CVE-2025-62395

    Last Modified: 14 Nov 2025

    A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

    Published: 23 Oct 2025
    4.3
    Medium

    CVE-2025-62400

    Last Modified: 14 Nov 2025

    Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

    Published: 23 Oct 2025
    7.5
    High

    CVE-2025-62399

    Last Modified: 14 Nov 2025

    Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

    Published: 23 Oct 2025
    5.4
    Medium

    CVE-2025-62398

    Last Modified: 14 Nov 2025

    A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

    Published: 23 Oct 2025
    5.3
    Medium

    CVE-2025-62397

    Last Modified: 14 Nov 2025

    The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

    Published: 23 Oct 2025
    5.3
    Medium

    CVE-2025-62396

    Last Modified: 14 Nov 2025

    An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

    Published: 23 Oct 2025
    4.3
    Medium

    CVE-2025-62394

    Last Modified: 14 Nov 2025

    Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

    Published: 23 Oct 2025
    4.3
    Medium

    CVE-2025-62393

    Last Modified: 14 Nov 2025

    A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.

    Published: 23 Oct 2025
    5.1
    Medium

    CVE-2025-10355

    Last Modified: 15 Apr 2026

    Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users to phishing sites or other malicious destinations via “/%2f%2f<MALICIOUS_DOMAIN>”.

    Published: 23 Oct 2025
    Unknown

    CVE-2024-14011

    Last Modified: 23 Oct 2025

    This is a duplicate.

    Published: 23 Oct 2025
    7.1
    High

    CVE-2025-41073

    Last Modified: 30 Oct 2025

    Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from the server, including those located in parent directories (e.g., ..\..\..), by exploiting the “direstudio” parameter in “/encuestas/integraweb[_v4]/integra/html/view/comprimir.php”.

    Published: 23 Oct 2025
    5.1
    Medium

    CVE-2025-40643

    Last Modified: 31 Oct 2025

    Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_job_submit.php”, using the “JobCreatedBy” parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

    Published: 23 Oct 2025
    4.8
    Medium

    CVE-2025-9981

    Last Modified: 17 Nov 2025

    QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 23 Oct 2025
    4.8
    Medium

    CVE-2025-9980

    Last Modified: 17 Nov 2025

    QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

    Published: 23 Oct 2025
    7.6
    High

    CVE-2025-10914

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Reflected XSS. This issue affects OBS (Student Affairs Information System): before V26.0401.

    Published: 23 Oct 2025
    5.4
    Medium

    CVE-2025-10727

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows Reflected XSS. This issue affects AcBakImzala: before v5.1.4.

    Published: 23 Oct 2025
    8.4
    High

    CVE-2025-61865

    Last Modified: 15 Apr 2026

    Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

    Published: 23 Oct 2025
    5.1
    Medium

    CVE-2025-54806

    Last Modified: 12 Nov 2025

    GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to the affected product, an arbitrary script may be executed on the user's web browser.

    Published: 23 Oct 2025
    4.6
    Medium

    CVE-2025-62499

    Last Modified: 15 Apr 2026

    Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit CategorySet of ContentType page.

    Published: 23 Oct 2025
    4.6
    Medium

    CVE-2025-54856

    Last Modified: 15 Apr 2026

    Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an arbitrary script may be executed on the web browser of the user who accesses Edit ContentData page.

    Published: 23 Oct 2025
    10
    Critical

    CVE-2025-12104

    Last Modified: 7 Nov 2025

    Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 23 Oct 2025
    5.5
    Medium

    CVE-2025-48430

    Last Modified: 15 Apr 2026

    Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server at will. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

    Published: 23 Oct 2025
    6.7
    Medium

    CVE-2025-48428

    Last Modified: 15 Apr 2026

    Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export a specific signing key while in use allowing them to deploy a compromised or counterfeit device on that site. This issue affects Command Centre Server: 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

    Published: 23 Oct 2025
    9.9
    Critical

    CVE-2025-47699

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.

    Published: 23 Oct 2025
    5.5
    Medium

    CVE-2025-41402

    Last Modified: 15 Apr 2026

    Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server:  9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.

    Published: 23 Oct 2025
    5.5
    Medium

    CVE-2025-35981

    Last Modified: 15 Apr 2026

    Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.2337 (MR3), 9.10.3194 (MR6).

    Published: 23 Oct 2025
    8.8
    High

    CVE-2025-11575

    Last Modified: 15 Apr 2026

    Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.

    Published: 23 Oct 2025
    7.5
    High

    CVE-2025-12105

    Last Modified: 29 Jun 2026

    A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

    Published: 23 Oct 2025
    6.1
    Medium

    CVE-2025-56008

    Last Modified: 20 May 2026

    Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

    Published: 23 Oct 2025
    6.1
    Medium

    CVE-2025-61413

    Last Modified: 31 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks.

    Published: 23 Oct 2025
    8.4
    High

    CVE-2025-54964

    Last Modified: 26 Feb 2026

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is network accessible, this may allow remote command execution.

    Published: 23 Oct 2025
    5.4
    Medium

    CVE-2025-12110

    Last Modified: 15 Apr 2026

    A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes the scope, and assumes that offline sessions are no longer available, but they are.

    Published: 23 Oct 2025
    5.3
    Medium

    CVE-2025-56009

    Last Modified: 20 May 2026

    Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

    Published: 23 Oct 2025
    6.5
    Medium

    CVE-2025-61464

    Last Modified: 30 Oct 2025

    gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

    Published: 23 Oct 2025
    5.9
    Medium

    CVE-2025-62813

    Last Modified: 29 Oct 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Oct 2025
    4.3
    Medium

    CVE-2025-54966

    Last Modified: 28 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain situations, including local file paths and SOCET GXP version information.

    Published: 23 Oct 2025
    6.5
    Medium

    CVE-2025-54963

    Last Modified: 28 Oct 2025

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job request that grants read access to files on the filesystem with the permissions of the GXP Job Service process. The path to a file is not sanitized for directory traversal, potentially allowing an attacker to read sensitive files in some configurations.

    Published: 23 Oct 2025
    7.5
    High

    CVE-2025-50950

    Last Modified: 28 Oct 2025

    Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

    Published: 23 Oct 2025
    6.1
    Medium

    CVE-2025-57240

    Last Modified: 15 Apr 2026

    Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute arbitrary code via the registration step.

    Published: 23 Oct 2025