CVE Feed

    Dashboard / CVE

    1.1
    Low

    CVE-2025-9577

    Last Modified: 9 Sept 2025

    A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited.

    Published: 28 Aug 2025
    5.1
    Medium

    CVE-2025-31971

    Last Modified: 15 Apr 2026

    AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.

    Published: 28 Aug 2025
    1.1
    Low

    CVE-2025-9576

    Last Modified: 9 Sept 2025

    A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    2.1
    Low

    CVE-2025-9575

    Last Modified: 4 Sept 2025

    A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Aug 2025
    4.4
    Medium

    CVE-2025-9195

    Last Modified: 15 Apr 2026

    Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a Denial of Service

    Published: 28 Aug 2025
    9.1
    Critical

    CVE-2025-58059

    Last Modified: 15 Apr 2026

    Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to before 13.1.2.RELEASE, any admin that can create or modify and execute process-definitions could gain access to sensitive data or resources. This includes but is not limited to: running executables on the application host, inspecting and extracting data from the host environment or application properties, spring beans (application context, database pooling). The following conditions have to be met in order to perform this attack: the user must be logged in, have the admin role, and must have some knowledge about running scripts via a the Camunda/Operator engine. Version 12.16.0 and 13.1.2 have been patched. It is strongly advised to upgrade. If no scripting is needed in any of the processes, it could be possible to disable it altogether via the ProcessEngineConfiguration. However, this workaround could lead to unexpected side-effects.

    Published: 28 Aug 2025
    Unknown

    CVE-2000-5001

    Last Modified: 22 Apr 2026

    This CVE has the been REJECTED and will not be published by the CNA.

    Published: 28 Aug 2025
    5.8
    Medium

    CVE-2025-58049

    Last Modified: 2 Sept 2025

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.

    Published: 28 Aug 2025
    9.9
    Critical

    CVE-2025-58048

    Last Modified: 15 Apr 2026

    Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands being run under the web server user context. This vulnerability was patched by commit 87c3db4 and was released under the version 1.2.11 tag without any other code modifications compared to version 1.2.10. If upgrading is not immediately possible, administrators can mitigate this vulnerability with one or more of the following measures: updating nginx config to download attachments instead of executing them or disallowing access to /storage/ fully using a WAF such as Cloudflare.

    Published: 28 Aug 2025
    7.5
    High

    CVE-2025-58047

    Last Modified: 15 Apr 2026

    Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-alpha.4. To mitigate downtime, have setup automatically restart processes that quit with an error.

    Published: 28 Aug 2025
    5.4
    Medium

    CVE-2025-31979

    Last Modified: 15 Apr 2026

    A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts, executables, or web shells, by bypassing client-side or server-side validation mechanisms.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-31977

    Last Modified: 29 Oct 2025

    HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

    Published: 28 Aug 2025
    Unknown

    CVE-2008-20002

    Last Modified: 22 Apr 2026

    This CVE has the been REJECTED and will not be published by the CNA.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-31972

    Last Modified: 29 Oct 2025

    HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.

    Published: 28 Aug 2025
    5.5
    Medium

    CVE-2025-58335

    Last Modified: 20 Jan 2026

    In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

    Published: 28 Aug 2025
    8.1
    High

    CVE-2025-58334

    Last Modified: 26 Feb 2026

    In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

    Published: 28 Aug 2025
    10
    Critical

    CVE-2025-57819

    Last Modified: 26 Feb 2026

    FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

    Published: 28 Aug 2025
    4.3
    Medium

    CVE-2025-57759

    Last Modified: 2 Sept 2025

    Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.

    Published: 28 Aug 2025
    4.3
    Medium

    CVE-2025-57758

    Last Modified: 2 Sept 2025

    Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying solely on the voter and additionally to check USER_CAN_ACCESS_MODULE.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-57757

    Last Modified: 2 Sept 2025

    Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.

    Published: 28 Aug 2025
    5.3
    Medium

    CVE-2025-57756

    Last Modified: 2 Sept 2025

    Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A workaround involves disabling the front end search.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-25010

    Last Modified: 26 Feb 2026

    Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.

    Published: 28 Aug 2025
    8.7
    High

    CVE-2024-13986

    Last Modified: 14 May 2026

    Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.

    Published: 28 Aug 2025
    7.5
    High

    CVE-2025-57767

    Last Modified: 20 Oct 2025

    Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Authenticate header, or an Authorization header with an incorrect realm was received without a previous 401 response being sent, the get_authorization_header() function in res_pjsip_authenticator_digest will return a NULL. This wasn't being checked before attempting to get the digest algorithm from the header which causes a SEGV. This issue has been patched in versions 20.15.2, 21.10.2, and 22.5.2. There are no workarounds.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-54995

    Last Modified: 3 Nov 2025

    Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2024-48908

    Last Modified: 15 Apr 2026

    lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version 2.0.2.

    Published: 28 Aug 2025
    8.5
    High

    CVE-2025-8067

    Last Modified: 29 Jun 2026

    A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the parameters of this handle, it receives the file descriptor list and index specifying the file where the loop device should be backed. The function itself validates the index value to ensure it isn't bigger than the maximum value allowed. However, it fails to validate the lower bound, allowing the index parameter to be a negative value. Under these circumstances, an attacker can cause the UDisks daemon to crash or perform a local privilege escalation by gaining access to files owned by privileged users.

    Published: 28 Aug 2025
    5.4
    Medium

    CVE-2024-49790

    Last Modified: 26 Nov 2025

    IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 28 Aug 2025
    7.8
    High

    CVE-2025-9578

    Last Modified: 15 Apr 2026

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40734.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-58127

    Last Modified: 23 Sept 2025

    Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-58126

    Last Modified: 23 Sept 2025

    Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-58125

    Last Modified: 23 Sept 2025

    Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-58124

    Last Modified: 7 Oct 2025

    Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.

    Published: 28 Aug 2025
    6.9
    Medium

    CVE-2025-58123

    Last Modified: 23 Sept 2025

    Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

    Published: 28 Aug 2025
    8.8
    High

    CVE-2025-54742

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8.

    Published: 28 Aug 2025
    9.8
    Critical

    CVE-2025-54738

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a through <= 4.7.9.

    Published: 28 Aug 2025
    5.8
    Medium

    CVE-2025-54734

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Slider: from n/a through <= 1.1.30.

    Published: 28 Aug 2025
    6.5
    Medium

    CVE-2025-54733

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28.

    Published: 28 Aug 2025
    8.1
    High

    CVE-2025-54731

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Object Injection.This issue affects YouTube Showcase: from n/a through <= 3.5.1.

    Published: 28 Aug 2025
    9.8
    Critical

    CVE-2025-54725

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-54724

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through <= 1.7.1.

    Published: 28 Aug 2025
    9.3
    Critical

    CVE-2025-54720

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL Injection.This issue affects Nest Addons: from n/a through <= 1.6.3.

    Published: 28 Aug 2025
    8.1
    High

    CVE-2025-54716

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ireca ireca allows PHP Local File Inclusion.This issue affects Ireca: from n/a through <= 1.8.5.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-54714

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-54710

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tiktok Feed: from n/a through <= 1.0.21.

    Published: 28 Aug 2025
    7.7
    High

    CVE-2025-54029

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export extendons-eo-wooimport-export allows Path Traversal.This issue affects WooCommerce csv import export: from n/a through <= 2.0.6.

    Published: 28 Aug 2025
    7.7
    High

    CVE-2025-53588

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Path Traversal.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2.

    Published: 28 Aug 2025
    8.1
    High

    CVE-2025-53584

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object Injection.This issue affects WP Ticket Customer Service Software & Support Ticket System: from n/a through <= 6.0.2.

    Published: 28 Aug 2025
    8.1
    High

    CVE-2025-53583

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Employee Spotlight: from n/a through <= 5.1.1.

    Published: 28 Aug 2025
    7.1
    High

    CVE-2025-53579

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha.eu Captcha.eu captcha-eu allows Reflected XSS.This issue affects Captcha.eu: from n/a through < 1.0.61.

    Published: 28 Aug 2025