CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2025-21053

    Last Modified: 23 Oct 2025

    Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21052

    Last Modified: 23 Oct 2025

    Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21051

    Last Modified: 23 Oct 2025

    Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 10 Oct 2025
    5.5
    Medium

    CVE-2025-21049

    Last Modified: 23 Oct 2025

    Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

    Published: 10 Oct 2025
    6.7
    Medium

    CVE-2025-21048

    Last Modified: 26 Feb 2026

    Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

    Published: 10 Oct 2025
    5.2
    Medium

    CVE-2025-21047

    Last Modified: 23 Oct 2025

    Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

    Published: 10 Oct 2025
    2.4
    Low

    CVE-2025-21046

    Last Modified: 23 Oct 2025

    Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

    Published: 10 Oct 2025
    4
    Medium

    CVE-2025-21045

    Last Modified: 9 Jan 2026

    Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

    Published: 10 Oct 2025
    5.7
    Medium

    CVE-2025-21044

    Last Modified: 26 Feb 2026

    Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 10 Oct 2025
    4.5
    Medium

    CVE-2025-10124

    Last Modified: 15 Apr 2026

    The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.

    Published: 10 Oct 2025
    1.9
    Low

    CVE-2025-11570

    Last Modified: 15 Apr 2026

    Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab. The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of [drupal/unified_twig_ext](https://www.drupal.org/project/unified_twig_ext)

    Published: 10 Oct 2025
    Unknown

    CVE-2025-11569

    Last Modified: 30 Oct 2025

    This record was withdrawn by its CNA; further investigation revealed it was not a security issue.

    Published: 10 Oct 2025
    8.4
    High

    CVE-2025-61871

    Last Modified: 15 Apr 2026

    NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

    Published: 10 Oct 2025
    5.3
    Medium

    CVE-2025-11449

    Last Modified: 15 Apr 2026

    ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.    ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configuration. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

    Published: 10 Oct 2025
    5.3
    Medium

    CVE-2025-11450

    Last Modified: 15 Apr 2026

    ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

    Published: 10 Oct 2025
    8.3
    High

    CVE-2025-60880

    Last Modified: 8 Jan 2026

    An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

    Published: 10 Oct 2025
    8.8
    High

    CVE-2025-60305

    Last Modified: 21 Oct 2025

    SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

    Published: 10 Oct 2025
    9.8
    Critical

    CVE-2025-60307

    Last Modified: 21 Oct 2025

    code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.

    Published: 10 Oct 2025
    9.9
    Critical

    CVE-2025-60306

    Last Modified: 20 Oct 2025

    code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

    Published: 10 Oct 2025
    8.3
    High

    CVE-2025-55903

    Last Modified: 15 Apr 2026

    A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

    Published: 10 Oct 2025
    9.4
    Critical

    CVE-2025-60269

    Last Modified: 20 Oct 2025

    JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-61505

    Last Modified: 3 Feb 2026

    e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` without validation, allowing attackers to craft malicious serialized data. This could lead to remote code execution, arbitrary file operations, or denial of service, depending on available PHP object gadgets in the codebase.

    Published: 10 Oct 2025
    4.1
    Medium

    CVE-2025-60308

    Last Modified: 20 Oct 2025

    code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. Malicious JavaScript code is entered in the Description field, which can leak the administrator's cookie information when browsing this room information

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-60838

    Last Modified: 28 Oct 2025

    An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 10 Oct 2025
    8.1
    High

    CVE-2025-60378

    Last Modified: 17 Nov 2025

    Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-60268

    Last Modified: 20 Oct 2025

    An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.

    Published: 10 Oct 2025
    6.1
    Medium

    CVE-2025-61319

    Last Modified: 16 Jan 2026

    ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.

    Published: 10 Oct 2025
    4.3
    Medium

    CVE-2025-62292

    Last Modified: 15 Apr 2026

    In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-61152

    Last Modified: 15 Apr 2026

    python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged token with arbitrary claims (e.g., is_admin=true) and bypass authentication checks, leading to privilege escalation or unauthorized access in applications that rely on python-jose for token validation. This issue is exploitable unless developers explicitly reject 'alg=none' tokens, which is not enforced by the library. NOTE: all parties agree that the issue is not relevant because it only occurs in a "verify_signature": False situation.

    Published: 10 Oct 2025
    7.3
    High

    CVE-2025-60869

    Last Modified: 15 Apr 2026

    Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visitors viewing the generated static site.

    Published: 10 Oct 2025
    6.5
    Medium

    CVE-2025-60868

    Last Modified: 15 Apr 2026

    The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.

    Published: 10 Oct 2025
    9.3
    Critical

    CVE-2025-61928

    Last Modified: 15 Apr 2026

    Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id: ctx.body.userId })`. When no session exists but `userId` is present in the request body, `authRequired` becomes false and the user object is set to the attacker-controlled ID. Server-only field validation only executes when `authRequired` is true (lines 280-295), allowing attackers to set privileged fields. No additional authentication occurs before the database operation, so the malicious payload is accepted. The same pattern exists in the update endpoint. This is a critical authentication bypass enabling full an unauthenticated attacker can generate an API key for any user and immediately gain complete authenticated access. This allows the attacker to perform any action as the victim user using the api key, potentially compromise the user data and the application depending on the victim's privileges. Version 1.3.26 contains a patch for the issue.

    Published: 9 Oct 2025
    4.6
    Medium

    CVE-2025-61926

    Last Modified: 15 Apr 2026

    Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and could not be configured at runtime. In practice, this meant that every deployment using Reviewbot would validate requests with the same secret unless the operator modified source code and rebuilt the component - an expectation that is not documented and is easy to miss. All Allstar releases prior to v4.5 that include the Reviewbot code path are affected. Deployments on v4.5 and later are not affected. Those who have not enabled or exposed the Reviewbot endpoint are not exposed to this issue.

    Published: 9 Oct 2025
    8.7
    High

    CVE-2016-15047

    Last Modified: 15 Apr 2026

    AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can supply crafted input to execute arbitrary system commands as root. Successful exploitation grants full control of the device, and - depending on deployment and whether the device stores credentials or has network reachability to internal systems - may enable credential theft, lateral movement, or data exfiltration. The archived SEARCH-LAB disclosure implies that this vulnerability was remediated in early 2017, but AVTECH has not defined an affected version range.

    Published: 9 Oct 2025
    4.8
    Medium

    CVE-2025-62240

    Last Modified: 12 Dec 2025

    Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user’s (1) First Name, (2) Middle Name or (3) Last Name text field.

    Published: 9 Oct 2025
    9.3
    Critical

    CVE-2025-59286

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

    Published: 9 Oct 2025
    9.3
    Critical

    CVE-2025-59272

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

    Published: 9 Oct 2025
    8.7
    High

    CVE-2025-59271

    Last Modified: 26 Feb 2026

    Redis Enterprise Elevation of Privilege Vulnerability

    Published: 9 Oct 2025
    9.3
    Critical

    CVE-2025-59252

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

    Published: 9 Oct 2025
    9.3
    Critical

    CVE-2025-55321

    Last Modified: 26 Feb 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Oct 2025
    8.8
    High

    CVE-2025-59247

    Last Modified: 22 Feb 2026

    Azure PlayFab Elevation of Privilege Vulnerability

    Published: 9 Oct 2025
    9.8
    Critical

    CVE-2025-59246

    Last Modified: 26 Feb 2026

    Azure Entra ID Elevation of Privilege Vulnerability

    Published: 9 Oct 2025
    9.6
    Critical

    CVE-2025-59218

    Last Modified: 26 Feb 2026

    Azure Entra ID Elevation of Privilege Vulnerability

    Published: 9 Oct 2025
    5.5
    Medium

    CVE-2025-11558

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

    Published: 9 Oct 2025
    5.5
    Medium

    CVE-2025-11557

    Last Modified: 24 Feb 2026

    A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

    Published: 9 Oct 2025
    6.3
    Medium

    CVE-2025-61783

    Last Modified: 15 Apr 2026

    Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.

    Published: 9 Oct 2025
    8.7
    High

    CVE-2025-61779

    Last Modified: 15 Apr 2026

    Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated (had the right key). This allowed any kbs-client to actually change the attestation policy. Version 0.15.0 fixes the issue.

    Published: 9 Oct 2025
    5.5
    Medium

    CVE-2025-43296

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

    Published: 9 Oct 2025
    8.1
    High

    CVE-2025-61773

    Last Modified: 15 Apr 2026

    pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the Captcha script endpoint and the Click'N'Load (CNL) Blueprint. This flaw allowed untrusted user input to be processed unsafely, which could be exploited by an attacker to inject arbitrary content into the web UI or manipulate request handling. The vulnerability could lead to client-side code execution (XSS) or other unintended behaviors when a malicious payload is submitted. user-supplied parameters from HTTP requests were not adequately validated or sanitized before being passed into the application logic and response generation. This allowed crafted input to alter the expected execution flow. CNL (Click'N'Load) blueprint exposed unsafe handling of untrusted parameters in HTTP requests. The application did not consistently enforce input validation or encoding, making it possible for an attacker to craft malicious requests. Version 0.5.0b3.dev91 contains a patch for the issue.

    Published: 9 Oct 2025
    7.2
    High

    CVE-2025-34248

    Last Modified: 15 Apr 2026

    D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due to improper sanitization of the deleteBackupList parameter. This can allow an authenticated attacker to delete arbitrary files impacting the integrity and availability of the system.

    Published: 9 Oct 2025