CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-54908

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54907

    Last Modified: 20 Feb 2026

    Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54906

    Last Modified: 26 Feb 2026

    Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.1
    High

    CVE-2025-54905

    Last Modified: 20 Feb 2026

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54904

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54903

    Last Modified: 20 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54902

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54899

    Last Modified: 26 Feb 2026

    Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54898

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    8.8
    High

    CVE-2025-54897

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54896

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54895

    Last Modified: 20 Feb 2026

    Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54894

    Last Modified: 20 Feb 2026

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54111

    Last Modified: 20 Feb 2026

    Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    8.8
    High

    CVE-2025-54110

    Last Modified: 20 Feb 2026

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    8.8
    High

    CVE-2025-54106

    Last Modified: 26 Feb 2026

    Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54102

    Last Modified: 26 Feb 2026

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    4.8
    Medium

    CVE-2025-54101

    Last Modified: 20 Feb 2026

    Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54099

    Last Modified: 20 Feb 2026

    Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54097

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54096

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54095

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-53798

    Last Modified: 20 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-53797

    Last Modified: 20 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-49734

    Last Modified: 20 Feb 2026

    Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    10
    Critical

    CVE-2025-54261

    Last Modified: 8 Oct 2025

    ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.

    Published: 9 Sept 2025
    4.9
    Medium

    CVE-2025-54250

    Last Modified: 12 Sept 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54247

    Last Modified: 12 Sept 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54246

    Last Modified: 12 Sept 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.

    Published: 9 Sept 2025
    7.7
    High

    CVE-2025-54248

    Last Modified: 12 Sept 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Scope is changed

    Published: 9 Sept 2025
    4.3
    Medium

    CVE-2025-54251

    Last Modified: 2 Oct 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.

    Published: 9 Sept 2025
    5.4
    Medium

    CVE-2025-54252

    Last Modified: 26 Feb 2026

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. This could result in bypassing security features within the application. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-54249

    Last Modified: 12 Sept 2025

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate server-side requests and bypass security controls allowing unauthorized read access.

    Published: 9 Sept 2025
    4.3
    Medium

    CVE-2025-58975

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Request Forgery.This issue affects Advanced Settings: from n/a through <= 3.1.1.

    Published: 9 Sept 2025
    4.3
    Medium

    CVE-2025-58976

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.

    Published: 9 Sept 2025
    4.9
    Medium

    CVE-2025-58977

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Server Side Request Forgery.This issue affects WP eBay Product Feeds: from n/a through <= 3.4.8.

    Published: 9 Sept 2025
    5.3
    Medium

    CVE-2025-58978

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Generator for WordPress: from n/a through <= 1.5.4.

    Published: 9 Sept 2025
    5.3
    Medium

    CVE-2025-58979

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BerqWP: from n/a through <= 2.2.53.

    Published: 9 Sept 2025
    5.3
    Medium

    CVE-2025-58980

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page to Static HTML/CSS: from n/a through <= 4.1.0.

    Published: 9 Sept 2025
    5.4
    Medium

    CVE-2025-58981

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.

    Published: 9 Sept 2025
    5.9
    Medium

    CVE-2025-58982

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline's Email Protector pixelines-email-protector allows Stored XSS.This issue affects Pixeline's Email Protector: from n/a through <= 1.3.8.

    Published: 9 Sept 2025
    5.9
    Medium

    CVE-2025-58983

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Include Me include-me allows Stored XSS.This issue affects Include Me: from n/a through <= 1.3.2.

    Published: 9 Sept 2025
    5.9
    Medium

    CVE-2025-58984

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-58985

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.3.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-58987

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Football Pool: from n/a through <= 2.12.6.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-58988

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tickets my-tickets allows Stored XSS.This issue affects My Tickets: from n/a through <= 2.0.22.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-58989

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7 allows Stored XSS.This issue affects Dynamic Text Field For Contact Form 7: from n/a through <= 1.0.

    Published: 9 Sept 2025
    7.1
    High

    CVE-2025-58991

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: from n/a through 0.7.4.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-58990

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affects ShopLentor: from n/a through <= 3.2.0.

    Published: 9 Sept 2025
    7.6
    High

    CVE-2025-58993

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor LMS: from n/a through <= 3.7.4.

    Published: 9 Sept 2025