CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2025-41019

    Last Modified: 15 Apr 2026

    SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.

    Published: 16 Oct 2025
    6.9
    Medium

    CVE-2025-55091

    Last Modified: 21 Oct 2025

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.

    Published: 16 Oct 2025
    9.3
    Critical

    CVE-2025-41018

    Last Modified: 21 Oct 2025

    SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.

    Published: 16 Oct 2025
    7.5
    High

    CVE-2025-62585

    Last Modified: 21 Oct 2025

    Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

    Published: 16 Oct 2025
    7.5
    High

    CVE-2025-62584

    Last Modified: 21 Oct 2025

    Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

    Published: 16 Oct 2025
    9.8
    Critical

    CVE-2025-62583

    Last Modified: 21 Oct 2025

    Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

    Published: 16 Oct 2025
    5.3
    Medium

    CVE-2025-10849

    Last Modified: 22 Apr 2026

    The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via an AJAX action in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to activate or deactivate arbitrary plugins.

    Published: 16 Oct 2025
    9.8
    Critical

    CVE-2025-10850

    Last Modified: 21 Apr 2026

    The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they registered with facebook or google social login and did not change their password. CVE-2025-23504 is likely a duplicate of this issue.

    Published: 16 Oct 2025
    9.8
    Critical

    CVE-2025-10742

    Last Modified: 21 Apr 2026

    The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited unauthenticated if the attacker knows which page contains the 'truelysell_edit_staff' shortcode.

    Published: 16 Oct 2025
    8.8
    High

    CVE-2025-10706

    Last Modified: 22 Apr 2026

    The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the affected site's server which may make remote code execution possible. Note: The required nonce for the vulnerability is in the CubeWP Framework plugin.

    Published: 16 Oct 2025
    6.9
    Medium

    CVE-2025-55090

    Last Modified: 21 Oct 2025

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.

    Published: 16 Oct 2025
    9.2
    Critical

    CVE-2025-55089

    Last Modified: 20 Jan 2026

    In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It could cause a remote execurtion after receiving a crafted sequence of packets

    Published: 16 Oct 2025
    6.9
    Medium

    CVE-2025-55084

    Last Modified: 21 Oct 2025

    In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.

    Published: 16 Oct 2025
    8.6
    High

    CVE-2025-58778

    Last Modified: 15 Apr 2026

    Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to the affected device, leading to information disclosure, altering the system configurations, or causing a denial of service (DoS) condition.

    Published: 16 Oct 2025
    5.3
    Medium

    CVE-2025-0275

    Last Modified: 21 Oct 2025

    HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

    Published: 16 Oct 2025
    5.3
    Medium

    CVE-2025-0274

    Last Modified: 21 Oct 2025

    HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

    Published: 16 Oct 2025
    6.4
    Medium

    CVE-2025-11814

    Last Modified: 15 Apr 2026

    The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.21.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Oct 2025
    4.3
    Medium

    CVE-2025-10700

    Last Modified: 21 Apr 2026

    The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 16 Oct 2025
    7.8
    High

    CVE-2025-62580

    Last Modified: 28 Oct 2025

    ASDA-Soft Stack-based Buffer Overflow Vulnerability

    Published: 16 Oct 2025
    7.8
    High

    CVE-2025-62579

    Last Modified: 28 Oct 2025

    ASDA-Soft Stack-based Buffer Overflow Vulnerability

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-11683

    Last Modified: 9 Mar 2026

    YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.

    Published: 16 Oct 2025
    5.5
    Medium

    CVE-2025-60358

    Last Modified: 23 Oct 2025

    radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

    Published: 16 Oct 2025
    5.5
    Medium

    CVE-2025-61554

    Last Modified: 15 Apr 2026

    A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access.

    Published: 16 Oct 2025
    6.1
    Medium

    CVE-2025-61539

    Last Modified: 21 Oct 2025

    Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-61514

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

    Published: 16 Oct 2025
    5.1
    Medium

    CVE-2025-60855

    Last Modified: 15 Apr 2026

    Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."

    Published: 16 Oct 2025
    5.4
    Medium

    CVE-2025-56700

    Last Modified: 15 Apr 2026

    Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter.

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-61330

    Last Modified: 15 Apr 2026

    A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/shadow configuration or even the absence of any password at all. Some of these devices have the Telnet service enabled by default, or users can choose to enable the Telnet service in other device management interfaces (e.g. /debug.asp or /debug_telnet.asp). In addition, these devices have related interfaces called Virtual Servers, which can map the devices to the public network, posing the risk of remote attacks. Therefore, attackers can obtain the highest root privileges of the devices through the Telnet service using the weak password hardcoded in the firmware (or without a password), and remote attacks are possible.

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-61540

    Last Modified: 23 Oct 2025

    SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

    Published: 16 Oct 2025
    8.2
    High

    CVE-2025-22381

    Last Modified: 15 Apr 2026

    Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

    Published: 16 Oct 2025
    7.1
    High

    CVE-2025-61541

    Last Modified: 6 Nov 2025

    Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain into the reset email. If a victim follows the poisoned link, the attacker can intercept the reset token and gain full control of the target account.

    Published: 16 Oct 2025
    5.4
    Medium

    CVE-2025-56699

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.

    Published: 16 Oct 2025
    7.1
    High

    CVE-2025-61543

    Last Modified: 15 Apr 2026

    A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links, enabling phishing attacks or account takeover.

    Published: 16 Oct 2025
    8.2
    High

    CVE-2025-61553

    Last Modified: 15 Apr 2026

    An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. Given it's a heap overflow in a privileged hypervisor context, exploitation may enable arbitrary code execution or guest-to-host privilege escalation.

    Published: 16 Oct 2025
    8.2
    High

    CVE-2025-61536

    Last Modified: 15 Apr 2026

    FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover.

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-60641

    Last Modified: 15 Apr 2026

    The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 and deserialized without validation or use of the allowed_classes option, allowing an attacker to inject arbitrary PHP objects. This can lead to malicious behavior, such as Remote Code Execution (RCE), SQL Injection, Path Traversal, or Denial of Service, depending on the availability of exploitable classes in the Vfront codebase or its dependencies.

    Published: 16 Oct 2025
    6.5
    Medium

    CVE-2025-60639

    Last Modified: 15 Apr 2026

    Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

    Published: 16 Oct 2025
    5.5
    Medium

    CVE-2025-43282

    Last Modified: 27 Apr 2026

    A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to cause unexpected system termination.

    Published: 15 Oct 2025
    5.5
    Medium

    CVE-2025-43313

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

    Published: 15 Oct 2025
    4.7
    Medium

    CVE-2025-43280

    Last Modified: 27 Apr 2026

    The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.

    Published: 15 Oct 2025
    7.8
    High

    CVE-2025-43281

    Last Modified: 2 Apr 2026

    The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

    Published: 15 Oct 2025
    8.8
    High

    CVE-2025-11619

    Last Modified: 3 Dec 2025

    Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.

    Published: 15 Oct 2025
    6.9
    Medium

    CVE-2025-62375

    Last Modified: 15 Apr 2026

    go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier the AWS attestor improperly verifies AWS EC2 instance identity documents. Verification can incorrectly succeed when a signature is not present or is empty, and when RSA signature verification fails. The attestor also embeds a single legacy global AWS public certificate and does not account for newer region specific certificates issued in 2024, making detection of forged documents difficult without additional trusted region data. An attacker able to supply or intercept instance identity document data (such as through Instance Metadata Service impersonation) can cause a forged identity document to be accepted, leading to incorrect trust decisions based on the attestation. This is fixed in go-witness 0.9.1 and witness 0.10.1. As a workaround, manually verify the included identity document, signature, and public key with standard tools (for example openssl) following AWS’s verification guidance, or disable use of the AWS attestor until upgraded.

    Published: 15 Oct 2025
    10
    Critical

    CVE-2025-11832

    Last Modified: 7 Nov 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

    Published: 15 Oct 2025
    7.4
    High

    CVE-2025-62371

    Last Modified: 4 Dec 2025

    OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when connecting to OpenSearch clusters if no certificate path was explicitly configured. This behavior bypasses SSL certificate validation, potentially allowing attackers to intercept and modify data in transit through man-in-the-middle attacks. The vulnerability affects connections to OpenSearch when the cert parameter is not explicitly provided. This issue has been patched in version 2.12.2. As a workaround, users can add the cert parameter to their OpenSearch sink or source configuration with the path to the cluster's CA certificate.

    Published: 15 Oct 2025
    9.4
    Critical

    CVE-2025-62410

    Last Modified: 15 Apr 2026

    In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom. The untrusted script and the rest of the application still run in the same Isolate/process, so attackers can deploy prototype pollution payloads to hijack important references like "process" in the example below, or to hijack control flow via flipping checks of undefined property. This vulnerability is due to an incomplete fix for CVE-2025-61927. The vulnerability is fixed in 20.0.2.

    Published: 15 Oct 2025
    8.3
    High

    CVE-2025-62381

    Last Modified: 15 Apr 2026

    sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type confusion, and potential remote code execution in downstream applications that rely on polluted objects. This vulnerability is fixed in 2.27.4.

    Published: 15 Oct 2025
    7.7
    High

    CVE-2025-62382

    Last Modified: 15 Apr 2026

    Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate's export workflow allows an authenticated operator to nominate any filesystem location as the thumbnail source for a video export. Because that path is copied verbatim into the publicly served clips directory, the feature can be abused to read arbitrary files that reside on the host running Frigate. In practice, a low-privilege user with API access can pivot from viewing camera footage to exfiltrating sensitive configuration files, secrets, or user data from the appliance itself. This behavior violates the principle of least privilege for the export subsystem and turns a convenience feature into a direct information disclosure vector, with exploitation hinging on a short race window while the background exporter copies the chosen file into place before cleanup runs. This vulnerability is fixed in 0.16.2.

    Published: 15 Oct 2025
    6.1
    Medium

    CVE-2025-62378

    Last Modified: 15 Apr 2026

    CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a logic flaw exists in the message command handler that affects how the commandName property is exposed to both middleware functions and command execution contexts when handling command aliases. When a message command is invoked using an alias, the ctx.commandName value reflects the alias rather than the canonical command name. This occurs in both middleware functions and within the command's own run function. Although not explicitly documented, CommandKit's examples and guidance around middleware usage implicitly convey that ctx.commandName represents the canonical command identifier. Middleware examples in the documentation consistently use ctx.commandName to reference the command being executed. Developers who assume ctx.commandName is canonical may introduce unintended behavior when relying on it for logic such as permission checks, rate limiting, or audit logging. This could allow unauthorized command execution or inaccurate access control decisions. Slash commands and context menu commands are not affected. This issue has been patched in version 1.2.0-rc.12, where ctx.commandName now consistently returns the actual canonical command name regardless of the alias used to invoke it.

    Published: 15 Oct 2025
    8.5
    High

    CVE-2025-10577

    Last Modified: 15 Apr 2026

    Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. HP is releasing updated audio packages to mitigate the potential vulnerabilities

    Published: 15 Oct 2025