CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-61890

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61891

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61892

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61893

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61894

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61895

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    Unknown

    CVE-2025-61887

    Last Modified: 4 Oct 2025

    Not used

    Published: 3 Oct 2025
    9.8
    Critical

    CVE-2025-6388

    Last Modified: 20 Apr 2026

    The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the custom_actions() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible for unauthenticated attackers to log in as any user, including administrators, granted they have access to the administrator's username.

    Published: 3 Oct 2025
    8.2
    High

    CVE-2025-0616

    Last Modified: 6 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel allows SQL Injection. This issue affects B2B - Netsis Panel: through 20251003. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Oct 2025
    8.4
    High

    CVE-2025-11223

    Last Modified: 15 Apr 2026

    Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead to loading a crafted DLL file in the same directory.

    Published: 3 Oct 2025
    5.9
    Medium

    CVE-2025-61589

    Last Modified: 20 Oct 2025

    Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows embedding images which then get rendered by Cursor in the chat box. An attacker can use this to exfiltrate sensitive information to a third-party attacker controlled server through an image fetch after successfully performing a prompt injection. A malicious model (or hallucination/backdoor) might also trigger this exploit at will. This issue requires prompt injection from malicious data (web, image upload, source code) in order to exploit. In that case, it can send sensitive information to an attacker-controlled external server. Some additional bypasses not covered in the initial fix to this issue were discovered, see GHSA-43wj-mwcc-x93p. This issue is fixed in version 1.7.

    Published: 3 Oct 2025
    8.7
    High

    CVE-2025-59536

    Last Modified: 23 Oct 2025

    Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

    Published: 3 Oct 2025
    5.1
    Medium

    CVE-2025-61599

    Last Modified: 8 Oct 2025

    Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitter"feature of EMLOG Pro 2.5.21 and below. An authenticated user with privileges to post a "Twitter" message can inject arbitrary JavaScript code. The malicious script is stored on the server and gets executed in the browser of any user, including administrators, when they click on the malicious post to view it. This issue does not currently have a fix.

    Published: 3 Oct 2025
    7.6
    High

    CVE-2025-61597

    Last Modified: 20 Oct 2025

    Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored cross‑site scripting (XSS) via the mail template settings. Once a malicious payload is saved, any subsequent visit to the settings page in an authenticated admin context will execute attacker‑controlled JavaScript, enabling session/token theft and full admin account takeover. This issue is fixed in version 2.5.22.

    Published: 3 Oct 2025
    6.8
    Medium

    CVE-2025-59300

    Last Modified: 8 Oct 2025

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 3 Oct 2025
    6.8
    Medium

    CVE-2025-59299

    Last Modified: 8 Oct 2025

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 3 Oct 2025
    6.8
    Medium

    CVE-2025-59298

    Last Modified: 8 Oct 2025

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 3 Oct 2025
    6.8
    Medium

    CVE-2025-59297

    Last Modified: 8 Oct 2025

    Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 3 Oct 2025
    6.4
    Medium

    CVE-2025-11241

    Last Modified: 15 Apr 2026

    The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.

    Published: 3 Oct 2025
    7.5
    High

    CVE-2025-11230

    Last Modified: 19 Dec 2025

    Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.

    Published: 3 Oct 2025
    7.5
    High

    CVE-2025-55972

    Last Modified: 16 Oct 2025

    A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.

    Published: 3 Oct 2025
    8.2
    High

    CVE-2025-56551

    Last Modified: 15 Oct 2025

    An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying a crafted GET request.

    Published: 3 Oct 2025
    7.2
    High

    CVE-2025-60787

    Last Modified: 10 Oct 2025

    MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60453

    Last Modified: 7 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60448

    Last Modified: 8 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2021-42193

    Last Modified: 19 Dec 2025

    nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60445

    Last Modified: 10 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the dayrui/Fcms/Library/Upload.php component, allowing attackers to inject malicious JavaScript code that executes when the uploaded file is viewed.

    Published: 3 Oct 2025
    6.5
    Medium

    CVE-2025-57423

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Content, GroupName, PersonName, lastUpdate, pool, and title. Due to insufficient input sanitisation, an unauthenticated remote attacker could inject arbitrary SQL commands via a crafted GET request, potentially leading to information disclosure or manipulation of the database.

    Published: 3 Oct 2025
    4.7
    Medium

    CVE-2025-55971

    Last Modified: 15 Oct 2025

    TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over TCP/16398 and attempts to retrieve externally referenced URIs, including attacker-controlled payloads. The blind SSRF allows for sending requests on behalf of the TV, which can be leveraged to probe for other internal or external services accessible by the device (e.g., 127.0.0.1:16XXX, LAN services, or internet targets), potentially enabling additional exploit chains.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60452

    Last Modified: 7 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60454

    Last Modified: 7 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the app\system\img\admin\img_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

    Published: 3 Oct 2025
    5.9
    Medium

    CVE-2025-60447

    Last Modified: 15 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, which allows administrators to input HTML code that is not properly sanitized, leading to persistent JavaScript execution.

    Published: 3 Oct 2025
    4.9
    Medium

    CVE-2025-60449

    Last Modified: 8 Oct 2025

    An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw allows authenticated administrators to scan and download not only the application’s source code but also potentially any file accessible on the server’s root directory.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60450

    Last Modified: 7 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

    Published: 3 Oct 2025
    6.1
    Medium

    CVE-2025-60451

    Last Modified: 7 Oct 2025

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, specifically in the website settings module. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.

    Published: 3 Oct 2025
    7.4
    High

    CVE-2025-59489

    Last Modified: 22 Oct 2025

    Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

    Published: 3 Oct 2025
    8.7
    High

    CVE-2025-61668

    Last Modified: 15 Apr 2026

    Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-61600

    Last Modified: 15 Apr 2026

    Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol parser which allows remote attackers to exhaust server memory, potentially triggering the system's out-of-memory (OOM) killer and causing a denial of service. The CommandParser implementation enforces size limits on its dynamic buffer in most parsing states, but several state handlers omit these validation checks. This issue is fixed in version 0.13.4. A workaround for this issue is to implement rate limiting and connection monitoring at the network level, however this does not provide complete protection.

    Published: 2 Oct 2025
    8.7
    High

    CVE-2025-61666

    Last Modified: 15 Apr 2026

    Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the Traccar configuration file. Versions 5.8 - 6.0 are only vulnerable if <entry key='web.override'>./override</entry> is set in the configuration file. Versions 6.1 - 6.8.1 are vulnerable by default as the web override is enabled by default. The vulnerable code is removed in version 6.9.0.

    Published: 2 Oct 2025
    8.7
    High

    CVE-2025-61665

    Last Modified: 7 Oct 2025

    WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and financial information of members without requiring authentication or authorization. This issue is fixed in version 3.5.0.

    Published: 2 Oct 2025
    4.8
    Medium

    CVE-2025-61606

    Last Modified: 7 Oct 2025

    WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=FuncionarioControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This issue is fixed in version 3.5.0.

    Published: 2 Oct 2025
    4.6
    Medium

    CVE-2025-54089

    Last Modified: 16 Oct 2025

    CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the attack are high and the victim must actively participate in the attack sequence. There is no impact to confidentiality or availability, there is a low impact to integrity.

    Published: 2 Oct 2025
    9.4
    Critical

    CVE-2025-61605

    Last Modified: 7 Oct 2025

    WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified in the /pet/profile_pet.php endpoint, specifically in the id_pet parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue is fixed in version 3.5.0.

    Published: 2 Oct 2025
    5.5
    Medium

    CVE-2025-54088

    Last Modified: 16 Oct 2025

    CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact to confidentiality is low and there is no impact to integrity or availability. There are high severity impacts to confidentiality, integrity, availability in subsequent systems.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-61604

    Last Modified: 7 Oct 2025

    WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The delete operation for the Almoxarifado entity is exposed via HTTP GET without CSRF protection, allowing a third-party site to trigger the action using the victim’s authenticated session. This issue is fixed in version 3.5.0.

    Published: 2 Oct 2025
    1.8
    Low

    CVE-2025-54087

    Last Modified: 16 Oct 2025

    CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is required. There is no direct impact to confidentiality, integrity, or availability. There is a low severity subsequent system impact to integrity.

    Published: 2 Oct 2025
    8.6
    High

    CVE-2025-10653

    Last Modified: 15 Apr 2026

    An unauthenticated debug port may allow access to the device file system.

    Published: 2 Oct 2025
    5.3
    Medium

    CVE-2025-54086

    Last Modified: 16 Oct 2025

    CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required are low and no user interaction is required. Impact to confidentiality is low, there is no impact to integrity or availability.

    Published: 2 Oct 2025
    9.4
    Critical

    CVE-2025-61603

    Last Modified: 7 Oct 2025

    WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue is fixed in version 3.5.0.

    Published: 2 Oct 2025
    8.8
    High

    CVE-2025-61595

    Last Modified: 15 Apr 2026

    MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentially amplifying the gas consumption exponentially. This is fixed in version 4.0.2.

    Published: 2 Oct 2025