CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2025-6430

    Last Modified: 20 Apr 2026

    When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

    Published: 24 Jun 2025
    9.1
    Critical

    CVE-2025-6427

    Last Modified: 20 Apr 2026

    An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

    Published: 24 Jun 2025
    8.8
    High

    CVE-2025-6426

    Last Modified: 20 Apr 2026

    The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

    Published: 24 Jun 2025
    6.5
    Medium

    CVE-2025-6429

    Last Modified: 20 Apr 2026

    Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

    Published: 24 Jun 2025
    4.3
    Medium

    CVE-2025-6425

    Last Modified: 20 Apr 2026

    An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

    Published: 24 Jun 2025
    9.8
    Critical

    CVE-2025-6424

    Last Modified: 20 Apr 2026

    A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

    Published: 24 Jun 2025
    7.1
    High

    CVE-2025-39205

    Last Modified: 30 Jan 2026

    A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

    Published: 24 Jun 2025
    8.5
    High

    CVE-2025-39204

    Last Modified: 26 Jan 2026

    A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

    Published: 24 Jun 2025
    7.1
    High

    CVE-2025-39203

    Last Modified: 26 Jan 2026

    A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.

    Published: 24 Jun 2025
    8.3
    High

    CVE-2025-39202

    Last Modified: 26 Jan 2026

    A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.

    Published: 24 Jun 2025
    6.9
    Medium

    CVE-2025-39201

    Last Modified: 26 Jan 2026

    A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.

    Published: 24 Jun 2025
    8.7
    High

    CVE-2025-2403

    Last Modified: 15 Apr 2026

    A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could potentially cause critical functions like LDCM (Line Distance Communication Module) to malfunction.

    Published: 24 Jun 2025
    7.1
    High

    CVE-2025-1718

    Last Modified: 15 Apr 2026

    An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

    Published: 24 Jun 2025
    7.5
    High

    CVE-2025-6206

    Last Modified: 22 Apr 2026

    The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. In order to exploit the vulnerability, there must be a value entered for the Stability.AI API key. The value can be arbitrary.

    Published: 24 Jun 2025
    7.5
    High

    CVE-2025-3092

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

    Published: 24 Jun 2025
    7.5
    High

    CVE-2025-3091

    Last Modified: 15 Apr 2026

    An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

    Published: 24 Jun 2025
    8.2
    High

    CVE-2025-3090

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

    Published: 24 Jun 2025
    6.4
    Medium

    CVE-2025-5258

    Last Modified: 15 Apr 2026

    The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Jun 2025
    9.8
    Critical

    CVE-2025-50213

    Last Modified: 11 Jul 2025

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.

    Published: 24 Jun 2025
    7.5
    High

    CVE-2025-2962

    Last Modified: 30 Oct 2025

    A denial-of-service issue in the dns implemenation could cause an infinite loop.

    Published: 24 Jun 2025
    9.3
    Critical

    CVE-2025-48890

    Last Modified: 15 Apr 2026

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.

    Published: 24 Jun 2025
    9.3
    Critical

    CVE-2025-43879

    Last Modified: 15 Apr 2026

    WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.

    Published: 24 Jun 2025
    4.8
    Medium

    CVE-2025-43877

    Last Modified: 15 Apr 2026

    WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who accessed WebGUI of the product.

    Published: 24 Jun 2025
    8.7
    High

    CVE-2025-41427

    Last Modified: 15 Apr 2026

    WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.

    Published: 24 Jun 2025
    5.3
    Medium

    CVE-2025-36519

    Last Modified: 15 Apr 2026

    Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.

    Published: 24 Jun 2025
    Unknown

    CVE-2025-53017

    Last Modified: 30 Jun 2025

    Reason: This candidate was issued in error.

    Published: 24 Jun 2025
    Unknown

    CVE-2025-53001

    Last Modified: 30 Jun 2025

    Reason: This candidate was issued in error.

    Published: 24 Jun 2025
    6.3
    Medium

    CVE-2025-47943

    Last Modified: 15 Apr 2026

    Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused by the usage of a vulnerable and outdated component: pdfjs-1.4.20 under public/plugins/. This issue has been fixed for gogs.io/gogs in version 0.13.3.

    Published: 24 Jun 2025
    10
    Critical

    CVE-2024-56731

    Last Modified: 21 Aug 2025

    Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by RUN_USER in the configuration. Allowing attackers to access and alter any users' code hosted on the same instance. This issue has been patched in version 0.13.3.

    Published: 24 Jun 2025
    8.6
    High

    CVE-2025-52566

    Last Modified: 27 Aug 2025

    llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer implementation (llama_vocab::tokenize) (src/llama-vocab.cpp:3036) resulting in unintended behavior in tokens copying size comparison. Allowing heap-overflowing llama.cpp inferencing engine with carefully manipulated text input during tokenization process. This issue has been patched in version b5721.

    Published: 24 Jun 2025
    1.7
    Low

    CVE-2025-52570

    Last Modified: 15 Apr 2026

    Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections (TCP, UDP and Unix socket) for the services letmeind and letmeinfwd. Therefore, the command line option num-connections is not effective and does not limit the number of simultaneously incoming connections. This issue has been patched in version 10.2.1.

    Published: 24 Jun 2025
    8.8
    High

    CVE-2025-52568

    Last Modified: 15 Apr 2026

    NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, disk image corruption, denial of service, and potential code execution. These issues stem from unchecked memory operations, unsafe typecasting, and improper input validation. This issue has been patched in version 0.0.3.

    Published: 24 Jun 2025
    8.1
    High

    CVE-2025-52560

    Last Modified: 13 Jan 2026

    Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs derived from the unvalidated Host header when the application_url configuration is unset (default behavior). This allows an attacker to craft a malicious password reset link that leaks the token to an attacker-controlled domain. If a victim (including an administrator) clicks the poisoned link, their account can be taken over. This affects all users who initiate a password reset while application_url is not set. This issue has been patched in version 1.2.46.

    Published: 24 Jun 2025
    7.5
    High

    CVE-2025-52574

    Last Modified: 15 Apr 2026

    SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. In v1.0.1, a whitelist was added that limits reading to only files under priv/data. This issue has been patched in version 1.0.1.

    Published: 24 Jun 2025
    4.1
    Medium

    CVE-2025-48470

    Last Modified: 9 Jul 2025

    Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, potentially leading to session hijacking, defacement, credential theft, or privilege escalation.

    Published: 24 Jun 2025
    9.6
    Critical

    CVE-2025-48469

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege escalation.

    Published: 24 Jun 2025
    6.4
    Medium

    CVE-2025-48468

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

    Published: 24 Jun 2025
    6.5
    Medium

    CVE-2025-48467

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and system unavailability.

    Published: 24 Jun 2025
    8.1
    High

    CVE-2025-48466

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

    Published: 24 Jun 2025
    3.1
    Low

    CVE-2025-48463

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.

    Published: 24 Jun 2025
    4.2
    Medium

    CVE-2025-48462

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate users from gaining access to the product.

    Published: 24 Jun 2025
    5
    Medium

    CVE-2025-48461

    Last Modified: 9 Jul 2025

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.

    Published: 24 Jun 2025
    9.3
    Critical

    CVE-2025-6560

    Last Modified: 15 Apr 2026

    Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.  The affected models are out of support; replacing the device is recommended.

    Published: 24 Jun 2025
    2.1
    Low

    CVE-2025-6552

    Last Modified: 15 Apr 2026

    A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Jun 2025
    9.3
    Critical

    CVE-2025-6559

    Last Modified: 15 Apr 2026

    Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.

    Published: 24 Jun 2025
    10
    Critical

    CVE-2025-34041

    Last Modified: 14 Jul 2026

    An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct and send malicious HTTP requests to the EDR Manager interface, leading to arbitrary command execution with elevated privileges. This flaw only affects the Chinese-language EDR builds. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-04 UTC.

    Published: 24 Jun 2025
    2
    Low

    CVE-2025-6551

    Last Modified: 8 Jul 2025

    A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Jun 2025
    1.9
    Low

    CVE-2025-6536

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library src/lib/core/datetime.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 24 Jun 2025
    10
    Critical

    CVE-2025-34040

    Last Modified: 29 Apr 2026

    An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-01 UTC.

    Published: 24 Jun 2025
    10
    Critical

    CVE-2025-34039

    Last Modified: 15 Apr 2026

    A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

    Published: 24 Jun 2025