CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2025-62237

    Last Modified: 12 Dec 2025

    Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

    Published: 10 Oct 2025
    4.8
    Medium

    CVE-2025-62238

    Last Modified: 12 Dec 2025

    Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected into a Account's “Name“ text field.

    Published: 10 Oct 2025
    4.6
    Medium

    CVE-2025-62239

    Last Modified: 12 Dec 2025

    Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via the crafted input in a workflow definition.

    Published: 10 Oct 2025
    5.4
    Medium

    CVE-2025-7374

    Last Modified: 22 Apr 2026

    The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This is due to insufficient login restrictions on inactive and pending accounts. This makes it possible for authenticated attackers, with Candidate- and Employer-level access and above, to log in to the site even if their account is inactive or pending.

    Published: 10 Oct 2025
    6.4
    Medium

    CVE-2025-7781

    Last Modified: 22 Apr 2026

    The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘cs_job_title’ parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Oct 2025
    5.3
    Medium

    CVE-2025-11579

    Last Modified: 16 Jan 2026

    github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61864

    Last Modified: 27 Oct 2025

    A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    5.4
    Medium

    CVE-2025-11190

    Last Modified: 17 Nov 2025

    The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

    Published: 10 Oct 2025
    7.3
    High

    CVE-2025-11189

    Last Modified: 17 Nov 2025

    The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

    Published: 10 Oct 2025
    7.3
    High

    CVE-2025-11188

    Last Modified: 14 Nov 2025

    The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61863

    Last Modified: 27 Oct 2025

    An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61862

    Last Modified: 27 Oct 2025

    An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61861

    Last Modified: 27 Oct 2025

    An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61860

    Last Modified: 27 Oct 2025

    An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61859

    Last Modified: 27 Oct 2025

    An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61857

    Last Modified: 27 Oct 2025

    An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    3.7
    Low

    CVE-2025-52625

    Last Modified: 25 Apr 2026

    A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61858

    Last Modified: 27 Oct 2025

    An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    5.4
    Medium

    CVE-2025-52624

    Last Modified: 27 Apr 2026

    A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.

    Published: 10 Oct 2025
    3.7
    Low

    CVE-2025-52635

    Last Modified: 27 Apr 2026

    A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61856

    Last Modified: 27 Oct 2025

    A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-52632

    Last Modified: 27 Apr 2026

    A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

    Published: 10 Oct 2025
    5.7
    Medium

    CVE-2025-37727

    Last Modified: 23 Dec 2025

    Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

    Published: 10 Oct 2025
    3.7
    Low

    CVE-2025-52630

    Last Modified: 27 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

    Published: 10 Oct 2025
    8.2
    High

    CVE-2025-25017

    Last Modified: 30 Oct 2025

    Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

    Published: 10 Oct 2025
    7.3
    High

    CVE-2025-30001

    Last Modified: 4 Nov 2025

    Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

    Published: 10 Oct 2025
    8.7
    High

    CVE-2025-25018

    Last Modified: 26 Feb 2026

    Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

    Published: 10 Oct 2025
    3.7
    Low

    CVE-2025-52634

    Last Modified: 27 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

    Published: 10 Oct 2025
    8.2
    High

    CVE-2025-52650

    Last Modified: 28 Apr 2026

    Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

    Published: 10 Oct 2025
    4.8
    Medium

    CVE-2025-41089

    Last Modified: 15 Apr 2026

    Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.

    Published: 10 Oct 2025
    5.1
    Medium

    CVE-2025-41088

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.

    Published: 10 Oct 2025
    3.1
    Low

    CVE-2025-52655

    Last Modified: 15 Apr 2026

    Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.

    Published: 10 Oct 2025
    5.1
    Medium

    CVE-2025-40640

    Last Modified: 3 Nov 2025

    Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_invoice_submit.php”, using the “customerName_0” parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

    Published: 10 Oct 2025
    7.1
    High

    CVE-2025-21050

    Last Modified: 23 Oct 2025

    Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21070

    Last Modified: 20 Oct 2025

    Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21069

    Last Modified: 20 Oct 2025

    Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21068

    Last Modified: 20 Oct 2025

    Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21067

    Last Modified: 20 Oct 2025

    Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21066

    Last Modified: 20 Oct 2025

    Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

    Published: 10 Oct 2025
    6.6
    Medium

    CVE-2025-21065

    Last Modified: 15 Apr 2026

    Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

    Published: 10 Oct 2025
    8.8
    High

    CVE-2025-21064

    Last Modified: 26 Feb 2026

    Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

    Published: 10 Oct 2025
    4.6
    Medium

    CVE-2025-21063

    Last Modified: 8 Jan 2026

    Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.

    Published: 10 Oct 2025
    7.8
    High

    CVE-2025-21062

    Last Modified: 26 Feb 2026

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

    Published: 10 Oct 2025
    7.1
    High

    CVE-2025-21061

    Last Modified: 28 Oct 2025

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

    Published: 10 Oct 2025
    5.5
    Medium

    CVE-2025-21060

    Last Modified: 28 Oct 2025

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.

    Published: 10 Oct 2025
    6.2
    Medium

    CVE-2025-21059

    Last Modified: 28 Oct 2025

    Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

    Published: 10 Oct 2025
    7.3
    High

    CVE-2025-21058

    Last Modified: 15 Apr 2026

    Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code with SystemUI privilege.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21057

    Last Modified: 20 Oct 2025

    Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

    Published: 10 Oct 2025
    4.3
    Medium

    CVE-2025-21055

    Last Modified: 23 Oct 2025

    Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21054

    Last Modified: 23 Oct 2025

    Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

    Published: 10 Oct 2025