CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-58267

    Last Modified: 15 Apr 2026

    A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

    Published: 2 Oct 2025
    9.3
    Critical

    CVE-2025-41064

    Last Modified: 15 Apr 2026

    Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-40992

    Last Modified: 15 Apr 2026

    Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/sociopro/profile/update_profile', affecting to 'name' parameter via POST. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal his/her cookie session details.

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-40991

    Last Modified: 8 Oct 2025

    Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-54293

    Last Modified: 10 Dec 2025

    Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-40990

    Last Modified: 8 Oct 2025

    Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to "title" and "description" parameters via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-40989

    Last Modified: 8 Oct 2025

    Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her cookie session details.

    Published: 2 Oct 2025
    4.7
    Medium

    CVE-2025-54468

    Last Modified: 15 Apr 2026

    A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.

    Published: 2 Oct 2025
    7.3
    High

    CVE-2025-61735

    Last Modified: 4 Nov 2025

    Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-61733

    Last Modified: 26 Feb 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-61734

    Last Modified: 4 Nov 2025

    Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

    Published: 2 Oct 2025
    5.9
    Medium

    CVE-2025-40646

    Last Modified: 15 Jul 2026

    Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information about customers by intercepting HTTP requests and searching for the JWT containing sensitive user information in the JWT payload.

    Published: 2 Oct 2025
    8.7
    High

    CVE-2025-40645

    Last Modified: 15 Apr 2026

    Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customers by sending an HTTP GET request to “/api/reserva/web/clients” using the “phone” parameter.

    Published: 2 Oct 2025
    4.8
    Medium

    CVE-2025-54292

    Last Modified: 10 Dec 2025

    Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.

    Published: 2 Oct 2025
    6.9
    Medium

    CVE-2025-54291

    Last Modified: 24 Oct 2025

    Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.

    Published: 2 Oct 2025
    6.9
    Medium

    CVE-2025-54290

    Last Modified: 24 Oct 2025

    Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.

    Published: 2 Oct 2025
    7.4
    High

    CVE-2025-54289

    Last Modified: 26 Feb 2026

    Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebSocket connection hijacking format

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-54288

    Last Modified: 24 Oct 2025

    Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers and obtain their metadata, configuration, and device information via spoofed process names in the command line.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-54287

    Last Modified: 22 Oct 2025

    Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 template engine.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-54286

    Last Modified: 26 Feb 2026

    Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.

    Published: 2 Oct 2025
    9.8
    Critical

    CVE-2025-9697

    Last Modified: 15 Apr 2026

    The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

    Published: 2 Oct 2025
    8.6
    High

    CVE-2025-9587

    Last Modified: 15 Apr 2026

    The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-61690

    Last Modified: 15 Apr 2026

    KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-61692

    Last Modified: 7 Oct 2025

    VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-61691

    Last Modified: 7 Oct 2025

    VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-58777

    Last Modified: 7 Oct 2025

    VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    8.4
    High

    CVE-2025-58776

    Last Modified: 15 Apr 2026

    KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    8.4
    High

    CVE-2025-58775

    Last Modified: 15 Apr 2026

    KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.

    Published: 2 Oct 2025
    8.7
    High

    CVE-2025-11020

    Last Modified: 15 Apr 2026

    An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.This issue affects SafePC Enterprise: V7.0.* (V7.0.YYYY.MM.DD) before V7.0.1, and V5.*.*.

    Published: 2 Oct 2025
    9.4
    Critical

    CVE-2025-11221

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTONE ChangeFlow allows Path Traversal, Accessing Functionality Not Properly Constrained by ACLs.This issue affects ChangeFlow: from All versions through v9.0.1.1.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-11182

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE ChangeFlow allows Path Traversal.This issue affects ChangeFlow: All versions to v9.0.1.1.

    Published: 2 Oct 2025
    7.2
    High

    CVE-2025-32942

    Last Modified: 15 Apr 2026

    SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.

    Published: 2 Oct 2025
    9.8
    Critical

    CVE-2025-59403

    Last Modified: 24 Nov 2025

    The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited to: /reboot, /logs, /crashpack, and /adb/enable. This results in multiple impacts including denial of service (DoS) via /reboot, information disclosure via /logs, and remote code execution (RCE) via /adb/enable. The latter specifically results in adb being started over TCP without debugging confirmation, providing an attacker in the LAN/WLAN with shell access.

    Published: 2 Oct 2025
    5.1
    Medium

    CVE-2025-57443

    Last Modified: 15 Apr 2026

    FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unprivileged local attackers to inject code into the FrostWire process via the DYLD_INSERT_LIBRARIES environment variable. This allows escalated privileges to arbitrary TCC-approved directories.

    Published: 2 Oct 2025
    6.5
    Medium

    CVE-2025-61096

    Last Modified: 7 Oct 2025

    PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

    Published: 2 Oct 2025
    6.1
    Medium

    CVE-2025-61087

    Last Modified: 7 Oct 2025

    SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-60663

    Last Modified: 7 Oct 2025

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.

    Published: 2 Oct 2025
    6.1
    Medium

    CVE-2025-56154

    Last Modified: 20 Jan 2026

    htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-49090

    Last Modified: 15 Apr 2026

    The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-60660

    Last Modified: 7 Oct 2025

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.

    Published: 2 Oct 2025
    9.8
    Critical

    CVE-2025-59407

    Last Modified: 24 Oct 2025

    The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a private key.

    Published: 2 Oct 2025
    6.5
    Medium

    CVE-2025-57305

    Last Modified: 16 Oct 2025

    VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

    Published: 2 Oct 2025
    6.5
    Medium

    CVE-2025-56019

    Last Modified: 27 Oct 2025

    An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are unable to connect, causing a denial of service. The attack requires proximity to the device, making it exploitable from an adjacent network location.

    Published: 2 Oct 2025
    5.3
    Medium

    CVE-2025-60661

    Last Modified: 7 Oct 2025

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

    Published: 2 Oct 2025
    7.1
    High

    CVE-2025-54315

    Last Modified: 15 Apr 2026

    The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.

    Published: 2 Oct 2025
    6.5
    Medium

    CVE-2025-56380

    Last Modified: 3 Oct 2025

    Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to the fieldname parameter

    Published: 2 Oct 2025
    6.5
    Medium

    CVE-2025-56381

    Last Modified: 3 Oct 2025

    ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.

    Published: 2 Oct 2025
    5.4
    Medium

    CVE-2025-56379

    Last Modified: 3 Oct 2025

    A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.

    Published: 2 Oct 2025
    5.4
    Medium

    CVE-2025-60782

    Last Modified: 7 Oct 2025

    PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creation or updates.

    Published: 2 Oct 2025
    7.5
    High

    CVE-2025-56161

    Last Modified: 30 Oct 2025

    YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile number, pay_money, expend_money.) are exposed in JSON responses. Route names vary per deployment (e.g. /api/goods.pinglun/list), but all call the same vulnerable model logic.

    Published: 2 Oct 2025