CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-49783

    Last Modified: 24 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data, they could exploit this vulnerability to use additional cryptographic methods to possibly extract the encrypted data.

    Published: 8 Jul 2025
    5.3
    Medium

    CVE-2024-49784

    Last Modified: 24 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If an authenticated remote attacker with access to the database or a local attacker with access to server files could extract the encrypted data values they could exploit this weaker algorithm to use additional cryptographic methods to possibly extract the encrypted data.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7190

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    6.1
    Medium

    CVE-2023-43039

    Last Modified: 17 Aug 2025

    IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

    Published: 8 Jul 2025
    8
    High

    CVE-2025-48384

    Last Modified: 26 Feb 2026

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

    Published: 8 Jul 2025
    8.6
    High

    CVE-2025-48385

    Last Modified: 15 Apr 2026

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform sufficient validation of the advertised bundles, which allows the remote side to perform protocol injection. This protocol injection can cause the client to write the fetched bundle to a location controlled by the adversary. The fetched content is fully controlled by the server, which can in the worst case lead to arbitrary code execution. The use of bundle URIs is not enabled by default and can be controlled by the bundle.heuristic config option. Some cases of the vulnerability require that the adversary is in control of where a repository will be cloned to. This either requires social engineering or a recursive clone with submodules. These cases can thus be avoided by disabling recursive clones. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

    Published: 8 Jul 2025
    6.3
    Medium

    CVE-2025-48386

    Last Modified: 15 Apr 2026

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The wincred credential helper uses a static buffer (target) as a unique key for storing and comparing against internal storage. This credential helper does not properly bounds check the available space remaining in the buffer before appending to it with wcsncat(), leading to potential buffer overflows. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7189

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    6.8
    Medium

    CVE-2025-4663

    Last Modified: 20 Feb 2026

    An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the corresponding ssh session is terminated with Control C (^c ) before supportsave completion. This issue affects Brocade Fabric OS 9.0.0 through 9.2.2

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7188

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-30312

    Last Modified: 13 Jul 2025

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-47135

    Last Modified: 13 Jul 2025

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-7363

    Last Modified: 15 Apr 2026

    The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an HtmlArmor object without sanitization and rendered directly into the page header, allowing attackers to inject arbitrary JavaScript. This issue affects Mediawiki - TitleIcon extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-7362

    Last Modified: 15 Apr 2026

    The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The vulnerability occurs in the file upload UI when the same filename is uploaded twice. This issue affects Mediawiki - MsUpload extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-0928

    Last Modified: 8 Jan 2026

    In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-53479

    Last Modified: 15 Apr 2026

    The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to inject JavaScript through the uselang=x-xss language override mechanism. This issue affects Mediawiki - CheckUser extension: from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7187

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-47988

    Last Modified: 26 Feb 2026

    Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49744

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49742

    Last Modified: 13 Feb 2026

    Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49740

    Last Modified: 13 Feb 2026

    Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49739

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49738

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49737

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    6.8
    Medium

    CVE-2025-47999

    Last Modified: 13 Feb 2026

    Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49733

    Last Modified: 26 Feb 2026

    Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49732

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49730

    Last Modified: 13 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49729

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49727

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49725

    Last Modified: 13 Feb 2026

    Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49724

    Last Modified: 13 Feb 2026

    Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    5.7
    Medium

    CVE-2025-49722

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-49718

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49714

    Last Modified: 26 Feb 2026

    Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-49706

    Last Modified: 26 Feb 2026

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49705

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49704

    Last Modified: 13 Feb 2026

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49703

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49702

    Last Modified: 22 May 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49701

    Last Modified: 13 Feb 2026

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49700

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49699

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49698

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-49697

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-49696

    Last Modified: 22 May 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    8.4
    High

    CVE-2025-49695

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49693

    Last Modified: 13 Feb 2026

    Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49685

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-49684

    Last Modified: 13 Feb 2026

    Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.

    Published: 8 Jul 2025