CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-3212

    Last Modified: 26 Feb 2026

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p4, from r50p0 through r51p0; Valhall GPU Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10093

    Last Modified: 29 Sept 2025

    A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Device Configuration Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 8 Sept 2025
    5.1
    Medium

    CVE-2025-40641

    Last Modified: 15 Apr 2026

    Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request using the product_name parameter in /Controller_Products/update. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10092

    Last Modified: 9 Oct 2025

    A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.

    Published: 8 Sept 2025
    5.1
    Medium

    CVE-2025-40642

    Last Modified: 15 Apr 2026

    Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code through the 'q' and 'engine' request parameters in /search.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10091

    Last Modified: 9 Oct 2025

    A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2025
    9.2
    Critical

    CVE-2025-5993

    Last Modified: 15 Apr 2026

    ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.

    Published: 8 Sept 2025
    6.1
    Medium

    CVE-2014-125128

    Last Modified: 19 Sept 2025

    'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.

    Published: 8 Sept 2025
    6.1
    Medium

    CVE-2019-25225

    Last Modified: 19 Sept 2025

    `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10090

    Last Modified: 9 Oct 2025

    A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 8 Sept 2025
    6.5
    Medium

    CVE-2025-58782

    Last Modified: 19 Nov 2025

    Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.

    Published: 8 Sept 2025
    2
    Low

    CVE-2025-10088

    Last Modified: 8 Sept 2025

    A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

    Published: 8 Sept 2025
    7.5
    High

    CVE-2025-41664

    Last Modified: 15 Apr 2026

    A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify firmware.

    Published: 8 Sept 2025
    7.4
    High

    CVE-2025-41708

    Last Modified: 15 Apr 2026

    Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.

    Published: 8 Sept 2025
    8.8
    High

    CVE-2025-41682

    Last Modified: 15 Apr 2026

    An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.

    Published: 8 Sept 2025
    2
    Low

    CVE-2025-10087

    Last Modified: 17 Nov 2025

    A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Such manipulation of the argument product_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 8 Sept 2025
    2.1
    Low

    CVE-2025-10086

    Last Modified: 9 Oct 2025

    A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. Affects another part than CVE-2025-9936.

    Published: 8 Sept 2025
    8.6
    High

    CVE-2025-8085

    Last Modified: 9 Feb 2026

    The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

    Published: 8 Sept 2025
    2.1
    Low

    CVE-2025-10085

    Last Modified: 17 Nov 2025

    A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

    Published: 8 Sept 2025
    2.1
    Low

    CVE-2025-10084

    Last Modified: 31 Oct 2025

    A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

    Published: 8 Sept 2025
    2.3
    Low

    CVE-2025-58422

    Last Modified: 15 Apr 2026

    RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the product’s management tool.

    Published: 8 Sept 2025
    2.1
    Low

    CVE-2025-10083

    Last Modified: 17 Nov 2025

    A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10082

    Last Modified: 9 Sept 2025

    A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2025
    2
    Low

    CVE-2025-10081

    Last Modified: 17 Nov 2025

    A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument website_image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 8 Sept 2025
    1.3
    Low

    CVE-2025-10080

    Last Modified: 15 Apr 2026

    A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10079

    Last Modified: 18 Sept 2025

    A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10078

    Last Modified: 9 Sept 2025

    A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10077

    Last Modified: 9 Sept 2025

    A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 8 Sept 2025
    5.5
    Medium

    CVE-2025-10076

    Last Modified: 9 Sept 2025

    A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

    Published: 8 Sept 2025
    2
    Low

    CVE-2025-10075

    Last Modified: 9 Sept 2025

    A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

    Published: 8 Sept 2025
    2
    Low

    CVE-2025-10074

    Last Modified: 9 Sept 2025

    A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument Tipos de Usuário/Descrição leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-22956

    Last Modified: 15 Apr 2026

    OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password for the windomain package.

    Published: 8 Sept 2025
    7.4
    High

    CVE-2022-50238

    Last Modified: 15 Apr 2026

    The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list have been excluded from the on-endpoint blocklist longer than the expected periodic monthly Windows updates. It is possible to fully synchronize the driver blocklist using WDAC policies. NOTE: The vendor explains that Windows Update provides a smaller, compatibility-focused driver blocklist for general users, while the full XML list is available for advanced users and organizations to customize at the risk of usability issues.

    Published: 8 Sept 2025
    3.7
    Low

    CVE-2025-51586

    Last Modified: 12 Sept 2025

    An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

    Published: 8 Sept 2025
    8.8
    High

    CVE-2025-52389

    Last Modified: 15 Apr 2026

    An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request.

    Published: 8 Sept 2025
    3.7
    Low

    CVE-2024-48341

    Last Modified: 18 Sept 2025

    dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-52161

    Last Modified: 12 Sept 2025

    Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.

    Published: 8 Sept 2025
    7.5
    High

    CVE-2025-52288

    Last Modified: 9 Oct 2025

    Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a denial of service or other unspecified impacts via repeated UE connect and disconnect message sequences.

    Published: 8 Sept 2025
    8.4
    High

    CVE-2025-55849

    Last Modified: 9 Oct 2025

    WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee

    Published: 8 Sept 2025
    8.1
    High

    CVE-2025-55998

    Last Modified: 29 Sept 2025

    A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter

    Published: 8 Sept 2025
    8.8
    High

    CVE-2025-56265

    Last Modified: 12 Sept 2025

    An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-56266

    Last Modified: 12 Sept 2025

    A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-56267

    Last Modified: 12 Sept 2025

    A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.

    Published: 8 Sept 2025
    7.3
    High

    CVE-2025-56630

    Last Modified: 9 Sept 2025

    FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-57141

    Last Modified: 12 Sept 2025

    rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.

    Published: 8 Sept 2025
    9.8
    Critical

    CVE-2025-57285

    Last Modified: 12 Sept 2025

    codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute arbitrary commands.

    Published: 8 Sept 2025
    7.4
    High

    CVE-2025-59033

    Last Modified: 15 Apr 2026

    The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may not be blocked, whether hypervisor-protected code integrity (HVCI) is enabled or not. NOTE: The vendor disputes this CVE ID assignment and states that the driver blocklist is intended for use with HVCI.

    Published: 8 Sept 2025
    2.1
    Low

    CVE-2025-10073

    Last Modified: 9 Sept 2025

    A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 7 Sept 2025
    2.1
    Low

    CVE-2025-10072

    Last Modified: 18 Sept 2026

    A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.11.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described improper access control behavior could no longer be reproduced."

    Published: 7 Sept 2025
    2.1
    Low

    CVE-2025-10071

    Last Modified: 9 Sept 2025

    A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

    Published: 7 Sept 2025