CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-59346

    Last Modified: 18 Sept 2025

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables users to force DragonFly2’s components to make requests to internal services that are otherwise not accessible to them. The issue arises because the Manager API accepts a user-supplied URL when creating a Preheat job with weak validation, peers can trigger other peers to fetch an arbitrary URL through pieceManager.DownloadSource, and internal HTTP clients follow redirects, allowing a request to a malicious server to be redirected to internal services. This can be used to probe or access internal HTTP endpoints. The vulnerability is fixed in version 2.1.0.

    Published: 17 Sept 2025
    7.7
    High

    CVE-2025-59345

    Last Modified: 13 Oct 2025

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in Manager web UI are accessible without authentication. Any user with network access to the Manager can create, delete, and modify jobs, and create preheat jobs. An unauthenticated adversary with network access to a Manager web UI uses /api/v1/jobs endpoint to create hundreds of useless jobs. The Manager is in a denial-of-service state, and stops accepting requests from valid administrators. This vulnerability is fixed in 2.1.0.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10613

    Last Modified: 20 Sept 2025

    A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

    Published: 17 Sept 2025
    7.2
    High

    CVE-2025-59416

    Last Modified: 15 Apr 2026

    The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since the API uses a POST request, it will make an article. This issue is fixed in v1.2.

    Published: 17 Sept 2025
    3.1
    Low

    CVE-2025-59414

    Last Modified: 3 Dec 2025

    Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vulnerability in Nuxt's Island payload revival mechanism allowed attackers to manipulate client-side requests to different endpoints within the same application domain when specific prerendering conditions are met. The vulnerability occurs in the client-side payload revival process (revive-payload.client.ts) where Nuxt Islands are automatically fetched when encountering serialized __nuxt_island objects. During prerendering, if an API endpoint returns user-controlled data containing a crafted __nuxt_island object, he data gets serialized with devalue.stringify and stored in the prerendered page. When a client navigates to the prerendered page, devalue.parse deserializes the payload. The Island reviver attempts to fetch /__nuxt_island/${key}.json where key could contain path traversal sequences. Update to Nuxt 3.19.0+ or 4.1.0+.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10608

    Last Modified: 18 Sept 2025

    A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit is now public and may be used.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10607

    Last Modified: 18 Sept 2025

    A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10606

    Last Modified: 18 Sept 2025

    A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-59342

    Last Modified: 15 Apr 2026

    esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.

    Published: 17 Sept 2025
    7.7
    High

    CVE-2025-59341

    Last Modified: 15 Apr 2026

    esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources).

    Published: 17 Sept 2025
    4.4
    Medium

    CVE-2025-59339

    Last Modified: 15 Apr 2026

    The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, and optionally move them to a remote storage periodically, if configured to. When running, the script properly rotates and encrypts the files using the provided GPG key(s), but silently fails to sign them, even if asked to.

    Published: 17 Sept 2025
    1.2
    Low

    CVE-2025-58767

    Last Modified: 30 Sept 2025

    REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches to fix these vulnerabilities.

    Published: 17 Sept 2025
    9
    Critical

    CVE-2025-58766

    Last Modified: 15 Apr 2026

    Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10605

    Last Modified: 18 Sept 2025

    A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10604

    Last Modified: 18 Sept 2025

    A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admin/edit_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

    Published: 17 Sept 2025
    5.2
    Medium

    CVE-2025-58432

    Last Modified: 22 Sept 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.

    Published: 17 Sept 2025
    4.8
    Medium

    CVE-2025-58431

    Last Modified: 22 Sept 2025

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10603

    Last Modified: 20 Sept 2025

    A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_forum/search_result.php. Executing manipulation of the argument Search can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10602

    Last Modified: 22 Sept 2025

    A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s1.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

    Published: 17 Sept 2025
    6.9
    Medium

    CVE-2025-35436

    Last Modified: 19 Dec 2025

    CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-35435

    Last Modified: 30 Sept 2025

    CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed in commit 89101a6.

    Published: 17 Sept 2025
    2.3
    Low

    CVE-2025-35434

    Last Modified: 30 Sept 2025

    CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.

    Published: 17 Sept 2025
    2.3
    Low

    CVE-2025-35433

    Last Modified: 30 Sept 2025

    CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.

    Published: 17 Sept 2025
    6.9
    Medium

    CVE-2025-35432

    Last Modified: 30 Sept 2025

    CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-35431

    Last Modified: 30 Sept 2025

    CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-35430

    Last Modified: 8 Oct 2025

    CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10601

    Last Modified: 22 Sept 2025

    A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the file /admin/index.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10600

    Last Modified: 22 Sept 2025

    A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10599

    Last Modified: 22 Sept 2025

    A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10598

    Last Modified: 22 Sept 2025

    A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown processing of the file /admin/search_product.php. Such manipulation of the argument group_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

    Published: 17 Sept 2025
    6.9
    Medium

    CVE-2025-10597

    Last Modified: 8 Oct 2025

    A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vulnerability affects unknown code of the file /Profilers/PriProfile/COUNT2.php. This manipulation of the argument cname causes sql injection. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.

    Published: 17 Sept 2025
    5.5
    Medium

    CVE-2025-10596

    Last Modified: 22 Sept 2025

    A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument usn results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 17 Sept 2025
    6.1
    Medium

    CVE-2025-9862

    Last Modified: 24 Feb 2026

    Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

    Published: 17 Sept 2025
    8.7
    High

    CVE-2025-10205

    Last Modified: 15 Apr 2026

    Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions

    Published: 17 Sept 2025
    7.3
    High

    CVE-2024-48842

    Last Modified: 15 Apr 2026

    Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10595

    Last Modified: 22 Sept 2025

    A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Sept 2025
    7.5
    High

    CVE-2025-40933

    Last Modified: 15 Apr 2026

    Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an MD5 hash of the epoch time and a call to the built-in rand function. The epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Predicable session ids could allow an attacker to gain access to systems.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10594

    Last Modified: 18 Sept 2025

    A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10593

    Last Modified: 18 Sept 2025

    A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-59476

    Last Modified: 4 Nov 2025

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-59474

    Last Modified: 4 Nov 2025

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

    Published: 17 Sept 2025
    4.3
    Medium

    CVE-2025-59475

    Last Modified: 4 Nov 2025

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).

    Published: 17 Sept 2025
    2.1
    Low

    CVE-2025-10592

    Last Modified: 20 Aug 2026

    A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-8463

    Last Modified: 5 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affects SecHard: before 3.6.2-20250805.

    Published: 17 Sept 2025
    9.8
    Critical

    CVE-2025-8077

    Last Modified: 15 Apr 2026

    A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is not changed immediately after deployment, any workload with network access within the cluster could use the default credentials to obtain an authentication token. This token can then be used to perform any operation via NeuVector APIs.

    Published: 17 Sept 2025
    4.7
    Medium

    CVE-2025-0879

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside Software Shopside App allows Cross-Site Scripting (XSS). This issue requires high privileges. This issue affects Shopside App: before 17.02.2025.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-54467

    Last Modified: 15 Apr 2026

    When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.

    Published: 17 Sept 2025
    5.3
    Medium

    CVE-2025-53884

    Last Modified: 15 Apr 2026

    NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).

    Published: 17 Sept 2025
    9.8
    Critical

    CVE-2025-10439

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection. This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7.

    Published: 17 Sept 2025
    4.7
    Medium

    CVE-2025-0546

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR allows Phishing, iFrame Overlay, Clickjacking, Forceful Browsing. This issue needs high privileges.  This issue affects MevzuatTR: before 12.02.2025.

    Published: 17 Sept 2025