CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-55170

    Last Modified: 14 Aug 2025

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a reflected cross-site scripting (XSS) vulnerability was identified in the /html/alterar_senha.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the verificacao and redir_config parameter. This issue has been patched in version 3.4.8.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49569

    Last Modified: 26 Feb 2026

    Substance3D - Viewer versions 0.25 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49560

    Last Modified: 26 Feb 2026

    Substance3D - Viewer versions 0.25 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    4.4
    Medium

    CVE-2025-36000

    Last Modified: 14 Aug 2025

    IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 12 Aug 2025
    10
    Critical

    CVE-2025-55169

    Last Modified: 14 Aug 2025

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.

    Published: 12 Aug 2025
    6.8
    Medium

    CVE-2024-48892

    Last Modified: 14 Aug 2025

    A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.

    Published: 12 Aug 2025
    6.7
    Medium

    CVE-2025-47857

    Last Modified: 26 Feb 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-32932

    Last Modified: 15 Aug 2025

    An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests

    Published: 12 Aug 2025
    6.7
    Medium

    CVE-2025-27759

    Last Modified: 26 Feb 2026

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI commands

    Published: 12 Aug 2025
    8.1
    High

    CVE-2024-26009

    Last Modified: 20 Apr 2026

    An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2024-52964

    Last Modified: 14 Aug 2025

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overwrite arbitrary files via FGFM crafted requests.

    Published: 12 Aug 2025
    5.3
    Medium

    CVE-2025-25248

    Last Modified: 9 Jun 2026

    An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.

    Published: 12 Aug 2025
    6.6
    Medium

    CVE-2023-45584

    Last Modified: 26 Feb 2026

    A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.

    Published: 12 Aug 2025
    8.1
    High

    CVE-2025-52970

    Last Modified: 14 Jan 2026

    A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

    Published: 12 Aug 2025
    7.2
    High

    CVE-2025-53744

    Last Modified: 9 Jun 2026

    An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.

    Published: 12 Aug 2025
    7.2
    High

    CVE-2025-49813

    Last Modified: 26 Feb 2026

    An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters.

    Published: 12 Aug 2025
    6.4
    Medium

    CVE-2025-32766

    Last Modified: 26 Feb 2026

    A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands

    Published: 12 Aug 2025
    9.8
    Critical

    CVE-2025-25256

    Last Modified: 18 Aug 2026

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

    Published: 12 Aug 2025
    4.4
    Medium

    CVE-2024-40588

    Last Modified: 14 Jan 2026

    Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.

    Published: 12 Aug 2025
    9.4
    Critical

    CVE-2025-55168

    Last Modified: 14 Aug 2025

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/saude/aplicar_medicamento.php endpoint, specifically in the id_fichamedica parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue has been patched in version 3.4.8.

    Published: 12 Aug 2025
    5.1
    Medium

    CVE-2025-43734

    Last Modified: 16 Dec 2025

    A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code in the “first display label” field in the configuration of a custom sort widget. This malicious payload is then reflected and executed by clay button taglib when refreshing the page.

    Published: 12 Aug 2025
    5.9
    Medium

    CVE-2025-36124

    Last Modified: 14 Aug 2025

    IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8 could allow a remote attacker to bypass security restrictions caused by a failure to honor JMS messaging configuration

    Published: 12 Aug 2025
    Unknown

    CVE-2025-8903

    Last Modified: 1 May 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a reservation duplicate of CVE-2026-2052 Notes: All CVE users should reference CVE-2026-2052 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-49556

    Last Modified: 15 Aug 2025

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction, and scope is unchanged.

    Published: 12 Aug 2025
    8.7
    High

    CVE-2025-49557

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject malicious scripts into vulnerable form fields. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field. Scope is changed.

    Published: 12 Aug 2025
    5.9
    Medium

    CVE-2025-49558

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the check of a resource's state and its use, allowing unauthorized write access. Exploitation of this issue does not require user interaction.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-49554

    Last Modified: 15 Aug 2025

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing the application to crash or become unresponsive. Exploitation of this issue does not require user interaction.

    Published: 12 Aug 2025
    5.3
    Medium

    CVE-2025-49559

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this issue does not require user interaction.

    Published: 12 Aug 2025
    8.1
    High

    CVE-2025-49555

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where the victim is authenticated, potentially allowing unauthorized access or modification of sensitive data. Exploitation of this issue requires user interaction in that a victim must visit a malicious website or click on a crafted link. Scope is changed.

    Published: 12 Aug 2025
    5.6
    Medium

    CVE-2025-20044

    Last Modified: 15 Apr 2026

    Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Aug 2025
    4.3
    Medium

    CVE-2025-49736

    Last Modified: 13 Feb 2026

    The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-49712

    Last Modified: 13 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.9
    High

    CVE-2025-49707

    Last Modified: 26 Feb 2026

    Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

    Published: 12 Aug 2025
    4.3
    Medium

    CVE-2025-49755

    Last Modified: 13 Feb 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    6.7
    Medium

    CVE-2025-48807

    Last Modified: 26 Feb 2026

    Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-53793

    Last Modified: 13 Feb 2026

    Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53789

    Last Modified: 26 Feb 2026

    Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53788

    Last Modified: 26 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8.4
    High

    CVE-2025-53784

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-53783

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.2
    High

    CVE-2025-53779

    Last Modified: 26 Feb 2026

    Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53778

    Last Modified: 26 Feb 2026

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50155

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-50157

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-53769

    Last Modified: 13 Feb 2026

    External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

    Published: 12 Aug 2025
    9.8
    Critical

    CVE-2025-53766

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    4.4
    Medium

    CVE-2025-53765

    Last Modified: 13 Feb 2026

    Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.

    Published: 12 Aug 2025
    8.4
    High

    CVE-2025-53740

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53739

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53738

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025