CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-33044

    Last Modified: 22 Oct 2025

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitation of this vulnerability may lead to memory corruption and impact Integrity and Availability.

    Published: 14 Oct 2025
    4.6
    Medium

    CVE-2025-22833

    Last Modified: 22 Oct 2025

    APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of this vulnerability may lead to arbitrary code execution.

    Published: 14 Oct 2025
    5.9
    Medium

    CVE-2025-22832

    Last Modified: 22 Oct 2025

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

    Published: 14 Oct 2025
    5.9
    Medium

    CVE-2025-22831

    Last Modified: 22 Oct 2025

    APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and loss of availability.

    Published: 14 Oct 2025
    7.2
    High

    CVE-2025-47856

    Last Modified: 16 Oct 2025

    Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-9178

    Last Modified: 15 Apr 2026

    A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-9177

    Last Modified: 15 Apr 2026

    A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web server. This could result in a web server crash however; this does not impact I/O control or communication . A power cycle is required to recover and utilize the webpage.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-7330

    Last Modified: 30 Oct 2025

    A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-10610

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows Blind SQL Injection. This issue affects Winsure: through Version dated 21.08.2025.

    Published: 14 Oct 2025
    5.3
    Medium

    CVE-2025-11498

    Last Modified: 15 Apr 2026

    An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a malicious link. The user would need to click on this link, after which the resulting CSV file addi-tionally needs to be manually opened.

    Published: 14 Oct 2025
    8.5
    High

    CVE-2025-7329

    Last Modified: 30 Oct 2025

    A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.

    Published: 14 Oct 2025
    9.9
    Critical

    CVE-2025-7328

    Last Modified: 29 Oct 2025

    Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore.

    Published: 14 Oct 2025
    8.1
    High

    CVE-2025-11720

    Last Modified: 20 Apr 2026

    The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-11718

    Last Modified: 20 Apr 2026

    When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.

    Published: 14 Oct 2025
    9.1
    Critical

    CVE-2025-11717

    Last Modified: 20 Apr 2026

    When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability was fixed in Firefox 144.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-11721

    Last Modified: 20 Apr 2026

    Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-11716

    Last Modified: 20 Apr 2026

    Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-11719

    Last Modified: 20 Apr 2026

    Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-11715

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-11712

    Last Modified: 20 Apr 2026

    A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-11708

    Last Modified: 20 Apr 2026

    Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    8.1
    High

    CVE-2025-11713

    Last Modified: 20 Apr 2026

    Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-11711

    Last Modified: 20 Apr 2026

    There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-11714

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-11710

    Last Modified: 20 Apr 2026

    A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-11709

    Last Modified: 20 Apr 2026

    A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

    Published: 14 Oct 2025
    8.5
    High

    CVE-2025-9067

    Last Modified: 20 Oct 2025

    A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2025-9124

    Last Modified: 15 Apr 2026

    A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a crafted CIP unconnected explicit message is sent. This can result in a major non-recoverable fault.

    Published: 14 Oct 2025
    8.5
    High

    CVE-2025-9068

    Last Modified: 24 Oct 2025

    A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2025-9064

    Last Modified: 28 Oct 2025

    A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-9063

    Last Modified: 28 Oct 2025

    An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2025-9066

    Last Modified: 15 Apr 2026

    A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2025-9437

    Last Modified: 15 Apr 2026

    A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-10228

    Last Modified: 5 Jun 2026

    Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affects Agentis: before 4.44.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-40812

    Last Modified: 21 Oct 2025

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-40811

    Last Modified: 21 Oct 2025

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-40810

    Last Modified: 21 Oct 2025

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-40809

    Last Modified: 21 Oct 2025

    A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

    Published: 14 Oct 2025
    6.7
    Medium

    CVE-2025-40774

    Last Modified: 20 Oct 2025

    A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords. Successful exploitation of this vulnerability allows an attacker to obtain and use valid user passwords. This can lead to unauthorized access to user accounts, data breaches, and potential system compromise.

    Published: 14 Oct 2025
    5.1
    Medium

    CVE-2025-40773

    Last Modified: 20 Oct 2025

    A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an attacker to potentially manipulate data belonging to other users.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-40772

    Last Modified: 10 Feb 2026

    A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation allows an attacker to impersonate other users within the application and steal their session data. This could enable unauthorized access to accounts and potentially lead to privilege escalation.

    Published: 14 Oct 2025
    9.3
    Critical

    CVE-2025-40771

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.4.24). Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.

    Published: 14 Oct 2025
    9.3
    Critical

    CVE-2025-40765

    Last Modified: 21 Oct 2025

    A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2025-40755

    Last Modified: 25 Nov 2025

    A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)

    Published: 14 Oct 2025
    8.3
    High

    CVE-2011-20002

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured.

    Published: 14 Oct 2025
    8.7
    High

    CVE-2011-20001

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.3). The web server interface of affected devices improperly processes incoming malformed HTTP traffic at high rate. This could allow an unauthenticated remote attacker to force the device entering the stop/defect state, thus creating a denial of service condition.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-20724

    Last Modified: 21 Oct 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418894; Issue ID: MSV-3475.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-20717

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00419946; Issue ID: MSV-3582.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-20716

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421149; Issue ID: MSV-3728.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-20715

    Last Modified: 26 Feb 2026

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421152; Issue ID: MSV-3731.

    Published: 14 Oct 2025