CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-57703

    Last Modified: 21 Aug 2025

    DIAEnergie - Reflected Cross-site Scripting

    Published: 18 Aug 2025
    5.9
    Medium

    CVE-2025-57702

    Last Modified: 21 Aug 2025

    DIAEnergie - Reflected Cross-site Scripting

    Published: 18 Aug 2025
    5.9
    Medium

    CVE-2025-57701

    Last Modified: 21 Aug 2025

    DIAEnergie - Reflected Cross-site Scripting

    Published: 18 Aug 2025
    7
    High

    CVE-2025-57700

    Last Modified: 21 Aug 2025

    DIAEnergie - Stored Cross-site Scripting

    Published: 18 Aug 2025
    2.9
    Low

    CVE-2025-9109

    Last Modified: 10 Sept 2025

    A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

    Published: 18 Aug 2025
    2.1
    Low

    CVE-2025-9108

    Last Modified: 15 Apr 2026

    Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch the attack remotely.

    Published: 18 Aug 2025
    2.1
    Low

    CVE-2025-9107

    Last Modified: 2 Sept 2025

    A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executing manipulation of the argument q can lead to cross site scripting. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    2
    Low

    CVE-2025-9106

    Last Modified: 2 Sept 2025

    A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. Performing manipulation of the argument Parecer/Conteúdos/Objetivos results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    2
    Low

    CVE-2025-9105

    Last Modified: 2 Sept 2025

    A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the file /planos-de-ensino-por-areas-de-conhecimento/ of the component Informações Adicionais Page. Such manipulation of the argument Parecer/Conteúdos/Objetivos leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    2
    Low

    CVE-2025-9104

    Last Modified: 2 Sept 2025

    A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /planos-de-aulas-por-disciplina/ of the component Informações Adicionais Page. This manipulation of the argument Parecer/Objeto de Conhecimento/Habilidades causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    1.9
    Low

    CVE-2025-9103

    Last Modified: 15 Apr 2026

    A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor declares this as "intended behavior, allowed for authorized administrators".

    Published: 18 Aug 2025
    1.9
    Low

    CVE-2025-9102

    Last Modified: 11 Sept 2025

    A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.mail.mobile.android.mail. The manipulation leads to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    2
    Low

    CVE-2025-9101

    Last Modified: 3 Sept 2025

    A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2025
    5.5
    Medium

    CVE-2025-9100

    Last Modified: 3 Sept 2025

    A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Aug 2025
    2.1
    Low

    CVE-2025-9099

    Last Modified: 15 Apr 2026

    A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    9.8
    Critical

    CVE-2025-31715

    Last Modified: 15 Apr 2026

    In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed.

    Published: 18 Aug 2025
    6.8
    Medium

    CVE-2025-31714

    Last Modified: 15 Apr 2026

    In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 18 Aug 2025
    8.4
    High

    CVE-2025-31713

    Last Modified: 15 Apr 2026

    In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 18 Aug 2025
    1.9
    Low

    CVE-2025-9098

    Last Modified: 15 Apr 2026

    A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    1.9
    Low

    CVE-2025-9097

    Last Modified: 15 Apr 2026

    A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cic_prod.bad. The manipulation leads to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Aug 2025
    8.5
    High

    CVE-2025-32992

    Last Modified: 15 Apr 2026

    Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.

    Published: 18 Aug 2025
    5.3
    Medium

    CVE-2025-55584

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

    Published: 18 Aug 2025
    6.5
    Medium

    CVE-2025-55590

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.

    Published: 18 Aug 2025
    6.5
    Medium

    CVE-2025-55585

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.

    Published: 18 Aug 2025
    7.5
    High

    CVE-2025-55586

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 18 Aug 2025
    7.5
    High

    CVE-2025-55587

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 18 Aug 2025
    7.5
    High

    CVE-2025-55588

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 18 Aug 2025
    6.5
    Medium

    CVE-2025-55589

    Last Modified: 21 Aug 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.

    Published: 18 Aug 2025
    9.8
    Critical

    CVE-2025-55591

    Last Modified: 21 Aug 2025

    TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

    Published: 18 Aug 2025
    2
    Low

    CVE-2025-9096

    Last Modified: 15 Apr 2026

    A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the library lib/rest/routes/apps.js of the component REST Endpoint. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Aug 2025
    7.5
    High

    CVE-2025-7342

    Last Modified: 15 Apr 2026

    A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerability was exploited during the build process, which requires an attacker to access the build VM and modify the image while the build is in progress.

    Published: 17 Aug 2025
    2
    Low

    CVE-2025-9095

    Last Modified: 15 Apr 2026

    A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the library lib/rest/routes/users.js of the component REST Endpoint. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Aug 2025
    2.1
    Low

    CVE-2025-9094

    Last Modified: 3 Dec 2025

    A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

    Published: 17 Aug 2025
    1.9
    Low

    CVE-2025-9093

    Last Modified: 11 Sept 2025

    A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 17 Aug 2025
    1.1
    Low

    CVE-2025-9091

    Last Modified: 21 Aug 2025

    A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 17 Aug 2025
    2.1
    Low

    CVE-2025-9090

    Last Modified: 21 Aug 2025

    A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Aug 2025
    7.4
    High

    CVE-2025-9089

    Last Modified: 21 Aug 2025

    A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Aug 2025
    7.4
    High

    CVE-2025-9088

    Last Modified: 21 Aug 2025

    A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the file /goform/formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Aug 2025
    7.4
    High

    CVE-2025-9087

    Last Modified: 21 Aug 2025

    A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/SetNetControlList of the component SetNetControlList Endpoint. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Aug 2025
    9.1
    Critical

    CVE-2023-3867

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup ksmbd does not consider the case of that smb2 session setup is in compound request. If this is the second payload of the compound, OOB read issue occurs while processing the first payload in the smb2_sess_setup().

    Published: 16 Aug 2025
    7.5
    High

    CVE-2023-3866

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session id and tree id in compound request. If first operation in the compound is SMB2 ECHO request, ksmbd bypass session and tree validation. So work->sess and work->tcon could be NULL. If secound request in the compound access work->sess or tcon, It cause NULL pointer dereferecing error.

    Published: 16 Aug 2025
    8.1
    High

    CVE-2023-3865

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_smb2_check_message doesn't validate hdr->NextCommand. If ->NextCommand is bigger than Offset + Length of smb2 write, It will allow oversized smb2 write length. It will cause OOB read in smb2_write.

    Published: 16 Aug 2025
    5.5
    Medium

    CVE-2025-38543

    Last Modified: 7 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return value with dma_alloc_coherent, in line with Robin's fix for vic.c in 'drm/tegra: vic: Fix DMA API misuse'.

    Published: 16 Aug 2025
    6.4
    Medium

    CVE-2025-8143

    Last Modified: 15 Apr 2026

    The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Aug 2025
    7.3
    High

    CVE-2025-8105

    Last Modified: 20 Apr 2026

    The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 16 Aug 2025
    6.5
    Medium

    CVE-2025-8878

    Last Modified: 21 Apr 2026

    The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 16 Aug 2025
    8.8
    High

    CVE-2025-8142

    Last Modified: 21 Apr 2026

    The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

    Published: 16 Aug 2025
    1
    Low

    CVE-2025-9092

    Last Modified: 15 Apr 2026

    Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) allows Excessive Allocation. This vulnerability is associated with program files org.Bouncycastle.Crypto.Fips.NativeLoader. This issue affects Bouncy Castle for Java - BC-FJA 2.1.0: from BC-FJA 2.1.0 through 2.1.0.

    Published: 16 Aug 2025
    6.4
    Medium

    CVE-2025-8719

    Last Modified: 20 Apr 2026

    The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Aug 2025
    5.3
    Medium

    CVE-2025-7499

    Last Modified: 22 Apr 2026

    The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.

    Published: 16 Aug 2025