CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2025-59731

    Last Modified: 15 Apr 2026

    When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we decompress and decode into the buffer td->rle_raw_data of size rle_raw_size at [1], and then at [2] we will access entries in this buffer up to (td->xsize - 1) * (td->ysize - 1) + rle_raw_size / 2, which may exceed rle_raw_size. We recommend upgrading to version 8.0 or beyond.

    Published: 6 Oct 2025
    5.7
    Medium

    CVE-2025-59730

    Last Modified: 15 Apr 2026

    When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution. This codec can encode the frame contents using a run-length encoding algorithm. There are no checks that the decoded frame fits in the allocated buffer, leading to a heap-buffer-overflow. process_frame_obj initializes the buffers based on the frame resolution: We recommend upgrading to version 8.0 or beyond.

    Published: 6 Oct 2025
    5.7
    Medium

    CVE-2025-59729

    Last Modified: 15 Apr 2026

    When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start of the allocated buffer. If we load a DHAV file that is larger than MAX_DURATION_BUFFER_SIZE bytes (0x100000) for example 0x101000 bytes, then at [0] we have size = 0x101000. At [1] we have end_buffer_size = 0x100000, and at [2] we have end_buffer_pos = 0x1000. The loop then scans backwards through the buffer looking for the dhav tag; when it is found, we'll calculate end_pos based on a 32-bit offset read from the buffer. There is subsequently a check [3] that end_pos is within the section of the file that has been copied into end_buffer, but it only correctly handles the cases where end_pos is before the start of the file or after the section copied into end_buffer, and not the case where end_pos is within the the file, but before the section copied into end_buffer. If we provide such an offset, (end_pos - end_buffer_pos) can underflow, resulting in the subsequent access at [4] occurring before the beginning of the allocation. We recommend upgrading to version 8.0 or beyond.

    Published: 6 Oct 2025
    8.7
    High

    CVE-2025-59728

    Last Modified: 15 Apr 2026

    When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer. We recommend upgrading to version 8.0 or beyond.

    Published: 6 Oct 2025
    7.4
    High

    CVE-2025-11327

    Last Modified: 24 Feb 2026

    A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 6 Oct 2025
    7.4
    High

    CVE-2025-11326

    Last Modified: 24 Feb 2026

    A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58579

    Last Modified: 27 Jan 2026

    Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.

    Published: 6 Oct 2025
    6.5
    Medium

    CVE-2025-58591

    Last Modified: 27 Jan 2026

    A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information.

    Published: 6 Oct 2025
    6.5
    Medium

    CVE-2025-58590

    Last Modified: 27 Jan 2026

    It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

    Published: 6 Oct 2025
    2.7
    Low

    CVE-2025-58589

    Last Modified: 27 Jan 2026

    When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.

    Published: 6 Oct 2025
    6.5
    Medium

    CVE-2025-58587

    Last Modified: 27 Jan 2026

    The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58586

    Last Modified: 27 Jan 2026

    For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

    Published: 6 Oct 2025
    7.4
    High

    CVE-2025-11325

    Last Modified: 24 Feb 2026

    A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58585

    Last Modified: 27 Jan 2026

    Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58584

    Last Modified: 27 Jan 2026

    In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58583

    Last Modified: 27 Jan 2026

    The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

    Published: 6 Oct 2025
    5.3
    Medium

    CVE-2025-58582

    Last Modified: 27 Jan 2026

    If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

    Published: 6 Oct 2025
    4.3
    Medium

    CVE-2025-58581

    Last Modified: 27 Jan 2026

    When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

    Published: 6 Oct 2025
    6.5
    Medium

    CVE-2025-58580

    Last Modified: 27 Jan 2026

    An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.

    Published: 6 Oct 2025
    3.8
    Low

    CVE-2025-58578

    Last Modified: 27 Jan 2026

    A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

    Published: 6 Oct 2025
    4.3
    Medium

    CVE-2025-9914

    Last Modified: 29 Jan 2026

    The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.

    Published: 6 Oct 2025
    4.5
    Medium

    CVE-2025-9913

    Last Modified: 29 Jan 2026

    JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

    Published: 6 Oct 2025
    7.4
    High

    CVE-2025-11324

    Last Modified: 24 Feb 2026

    A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 6 Oct 2025
    7.4
    High

    CVE-2025-11323

    Last Modified: 8 Jan 2026

    A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    6.3
    Medium

    CVE-2025-9710

    Last Modified: 15 Apr 2026

    The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.

    Published: 6 Oct 2025
    4.3
    Medium

    CVE-2025-9703

    Last Modified: 15 Apr 2026

    The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

    Published: 6 Oct 2025
    2.9
    Low

    CVE-2025-11322

    Last Modified: 15 Apr 2026

    A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can lead to weak password requirements. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is regarded as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    8.4
    High

    CVE-2025-57781

    Last Modified: 15 Apr 2026

    The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.

    Published: 6 Oct 2025
    2.1
    Low

    CVE-2025-11321

    Last Modified: 15 Apr 2026

    A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the argument subjectId results in authorization bypass. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 6 Oct 2025
    2.1
    Low

    CVE-2025-11320

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 6 Oct 2025
    2.1
    Low

    CVE-2025-11319

    Last Modified: 15 Apr 2026

    A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the argument ai causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11318

    Last Modified: 3 Nov 2025

    A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of the argument File results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11317

    Last Modified: 3 Nov 2025

    A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findRolePage of the file findSingConfigPage.do. The manipulation of the argument sort leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11316

    Last Modified: 3 Nov 2025

    A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this issue is the function findCategoryPage of the file findCategoryPage.do. Executing manipulation of the argument tenantId can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11315

    Last Modified: 3 Nov 2025

    A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. Performing manipulation of the argument sort results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11314

    Last Modified: 3 Nov 2025

    A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11313

    Last Modified: 3 Nov 2025

    A flaw has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This impacts the function findRolePage of the file findRolePage.do. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11312

    Last Modified: 3 Nov 2025

    A vulnerability was detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findModulePage of the file findModulePage.do. The manipulation of the argument sort results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    5.5
    Medium

    CVE-2025-11311

    Last Modified: 3 Nov 2025

    A security vulnerability has been detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. The impacted element is the function findTenantPage of the file findTenantPage.do. The manipulation of the argument sort leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Oct 2025
    9.1
    Critical

    CVE-2025-57247

    Last Modified: 15 Apr 2026

    The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access control implementation in whitelist management functions. The setColdWhiteList() and setSpecialAddress() functions in the base ERC20 contract are declared as public without proper access control modifiers, allowing any user to bypass transfer restrictions and manipulate special address settings. This enables unauthorized users to circumvent cold time transfer restrictions and potentially disrupt dividend distribution mechanisms, leading to privilege escalation and violation of the contract's intended tokenomics.

    Published: 6 Oct 2025
    7.3
    High

    CVE-2025-60967

    Last Modified: 10 Oct 2025

    Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

    Published: 6 Oct 2025
    9.1
    Critical

    CVE-2025-60965

    Last Modified: 10 Oct 2025

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified impacts.

    Published: 6 Oct 2025
    8.2
    High

    CVE-2025-60963

    Last Modified: 10 Oct 2025

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

    Published: 6 Oct 2025
    6.1
    Medium

    CVE-2025-60961

    Last Modified: 10 Oct 2025

    Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

    Published: 6 Oct 2025
    8.2
    High

    CVE-2025-60960

    Last Modified: 10 Oct 2025

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

    Published: 6 Oct 2025
    8.2
    High

    CVE-2025-60959

    Last Modified: 10 Oct 2025

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

    Published: 6 Oct 2025
    5.4
    Medium

    CVE-2025-28129

    Last Modified: 21 Oct 2025

    Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

    Published: 6 Oct 2025
    6.5
    Medium

    CVE-2025-61224

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

    Published: 6 Oct 2025
    5.4
    Medium

    CVE-2025-61198

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 - System version 2.5.26, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

    Published: 6 Oct 2025
    8.9
    High

    CVE-2025-61197

    Last Modified: 15 Apr 2026

    An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote attacker to escalate privileges via the application stores user privilege/role information in client-side browser storage

    Published: 6 Oct 2025