CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2025-6065

    Last Modified: 22 Apr 2026

    The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 14 Jun 2025
    7.2
    High

    CVE-2025-5487

    Last Modified: 21 Apr 2026

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Administrators can configure the plugin to allow access to this functionality to authors and higher.

    Published: 14 Jun 2025
    7.2
    High

    CVE-2025-3234

    Last Modified: 22 Apr 2026

    The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Administrators have the ability to extend file manager usage privileges to lower-level users including subscribers, which would make this vulnerability more severe on such sites.

    Published: 14 Jun 2025
    4.3
    Medium

    CVE-2025-6059

    Last Modified: 20 Apr 2026

    The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possible for unauthenticated attackers to perform several administrative actions, including deleting the cache, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 14 Jun 2025
    8.5
    High

    CVE-2025-33108

    Last Modified: 24 Aug 2025

    IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with component access to the host operating system.

    Published: 14 Jun 2025
    8.1
    High

    CVE-2025-24919

    Last Modified: 15 Apr 2026

    A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault firmware and have it craft a malicious response to trigger this vulnerability.

    Published: 13 Jun 2025
    8.8
    High

    CVE-2025-25215

    Last Modified: 15 Apr 2026

    An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability.

    Published: 13 Jun 2025
    5.2
    Medium

    CVE-2025-6083

    Last Modified: 8 Jan 2026

    In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.

    Published: 13 Jun 2025
    8.8
    High

    CVE-2025-25050

    Last Modified: 15 Apr 2026

    An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this vulnerability.

    Published: 13 Jun 2025
    8.8
    High

    CVE-2025-24922

    Last Modified: 15 Apr 2026

    A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this vulnerability.

    Published: 13 Jun 2025
    8.4
    High

    CVE-2025-24311

    Last Modified: 15 Apr 2026

    An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability.

    Published: 13 Jun 2025
    4.4
    Medium

    CVE-2025-49598

    Last Modified: 15 Apr 2026

    conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe use of the eval function when parsing version information from a custom-formatted meta.yaml file. An attacker controlling meta.yaml can inject malicious code into the version assignment, which is executed during file processing, leading to arbitrary code execution. Exploitation requires an attacker to modify the recipe file by manipulating the RECIPE_DIR variable and introducing a malicious meta.yaml file. While this is more feasible in CI/CD pipelines, it is uncommon in typical environments, reducing overall risk. This vulnerability is fixed in 4.15.0.

    Published: 13 Jun 2025
    9.4
    Critical

    CVE-2025-49596

    Last Modified: 15 Apr 2026

    The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

    Published: 13 Jun 2025
    3.9
    Low

    CVE-2025-49597

    Last Modified: 15 Apr 2026

    handcraftedinthealps goodby-csv is a highly memory efficient, flexible and extendable open-source CSV import/export library. Prior to 1.4.3, goodby-csv could be used as part of a chain of methods that is exploitable when an insecure deserialization vulnerability exists in an application. This so-called "gadget chain" presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability. The problem is patched with Version 1.4.3.

    Published: 13 Jun 2025
    6.4
    Medium

    CVE-2025-49587

    Last Modified: 3 Sept 2025

    XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as raw HTML, allowing XSS attacks. While the notification displayer executes Velocity, the existing generic analyzer already warns admins before editing Velocity code. Note that warnings before editing documents with dangerous properties have only been introduced in XWiki 15.9, before that version, this was a known issue and the advice was simply to be careful. This vulnerability has been patched in XWiki 15.10.16, 16.4.7, and 16.10.2 by adding a required rights analyzer that warns the admin before editing about the possibly malicious code.

    Published: 13 Jun 2025
    8.7
    High

    CVE-2025-49586

    Last Modified: 3 Sept 2025

    XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been fixed in XWiki 17.0.0, 16.4.7, and 16.10.3.

    Published: 13 Jun 2025
    8.6
    High

    CVE-2025-49585

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that same document is later edited by a user with script, admin, or programming right, malicious code could be executed with the rights of the editing user without prior warning. In particular, this concerns custom display code, the script of computed properties and queries in database list properties. Note that warnings before editing documents with dangerous properties have only been introduced in XWiki 15.9, before that version, this was a known issue and the advice was simply to be careful. This has been patched in XWiki 16.10.2, 16.4.7 and 15.10.16 by adding an analysis for the respective XClass properties.

    Published: 13 Jun 2025
    8.7
    High

    CVE-2025-49584

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a page property is accessible, this is the default for an XWiki installation. This allows an attacker to get titles of pages whose reference is known, one title per request. This doesn't affect fully private wikis as the REST endpoint checks access rights on the XClass definition. The impact on confidentiality depends on the strategy for page names. By default, page names match the title, so the impact should be low but if page names are intentionally obfuscated because the titles are sensitive, the impact could be high. This has been fixed in XWiki 16.4.7, 16.10.3 and 17.0.0 by adding access control checks before getting the title of any page.

    Published: 13 Jun 2025
    5.1
    Medium

    CVE-2025-49583

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No malicious code can be executed, though, as while these templates allow Velocity code, the existing generic analyzer already warns admins before editing Velocity code. The main impact would thus be to send spam, e.g., with phishing links to other users or to hide notifications about other attacks. Note that warnings before editing documents with dangerous properties have only been introduced in XWiki 15.9, before that version, this was a known issue and the advice was simply to be careful. This has been patched in XWiki 16.10.2, 16.4.7 and 15.10.16 by adding an analysis for the respective XClass properties.

    Published: 13 Jun 2025
    8.6
    High

    CVE-2025-49582

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required rights analyzers that trigger these warnings are incomplete, allowing an attacker to hide malicious content. For most macros, the existing analyzers don't consider non-lowercase parameters. Further, most macro parameters that can contain XWiki syntax like titles of information boxes weren't analyzed at all. Similarly, the "source" parameters of the content and context macro weren't anylzed even though they could contain arbitrary XWiki syntax. In the worst case, this could allow a malicious to add malicious script macros including Groovy or Python macros to a page that are then executed after another user with programming righs edits the page, thus allowing remote code execution. The required rights analyzers have been made more robust and extended to cover those cases in XWiki 16.4.7, 16.10.3 and 17.0.0.

    Published: 13 Jun 2025
    8.7
    High

    CVE-2025-49581

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. The main problem is that if a wiki macro parameter allows wiki syntax, its default value is executed with the rights of the author of the document where it is used. This can be exploited by overriding a macro like the children macro that is used in a page that has programming right like the page XWiki.ChildrenMacro and thus allows arbitrary script macros. This vulnerability has been patched in XWiki 16.4.7, 16.10.3 and 17.0.0 by executing wiki parameters with the rights of the wiki macro's author when the parameter's value is the default value.

    Published: 13 Jun 2025
    8.5
    High

    CVE-2025-49580

    Last Modified: 3 Sept 2025

    XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts contained in xobjects that should have never been executed. This vulnerability is fixed in 17.1.0-rc-1, 16.10.4, and 16.4.7.

    Published: 13 Jun 2025
    8.6
    High

    CVE-2025-48915

    Last Modified: 18 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

    Published: 13 Jun 2025
    8.6
    High

    CVE-2025-48914

    Last Modified: 18 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.15.

    Published: 13 Jun 2025
    7.3
    High

    CVE-2025-48920

    Last Modified: 8 Jul 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.

    Published: 13 Jun 2025
    5
    Medium

    CVE-2025-48919

    Last Modified: 17 Jul 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.

    Published: 13 Jun 2025
    5
    Medium

    CVE-2025-48917

    Last Modified: 8 Jul 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU Cookie Compliance (GDPR Compliance): from 0.0.0 before 1.26.0.

    Published: 13 Jun 2025
    8.8
    High

    CVE-2025-48918

    Last Modified: 17 Jul 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 before 1.10.0.

    Published: 13 Jun 2025
    6.5
    Medium

    CVE-2025-48916

    Last Modified: 10 Jul 2025

    Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.

    Published: 13 Jun 2025
    9.4
    Critical

    CVE-2025-6030

    Last Modified: 15 Apr 2026

    Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto.  Attack confirmed on other KIA Models in Ecuador.

    Published: 13 Jun 2025
    8.4
    High

    CVE-2025-36631

    Last Modified: 23 Oct 2025

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.

    Published: 13 Jun 2025
    9.4
    Critical

    CVE-2025-6029

    Last Modified: 15 Apr 2026

    Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release.  CVE Record will be updated once this is clarified.

    Published: 13 Jun 2025
    8.8
    High

    CVE-2025-36633

    Last Modified: 26 Feb 2026

    In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50148

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50149

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50150

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50142

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50143

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50144

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50145

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50146

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    Unknown

    CVE-2025-50147

    Last Modified: 14 Jun 2025

    Not used

    Published: 13 Jun 2025
    8.6
    High

    CVE-2025-49468

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.

    Published: 13 Jun 2025
    10
    Critical

    CVE-2025-29902

    Last Modified: 15 Apr 2026

    Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.

    Published: 13 Jun 2025
    2
    Low

    CVE-2025-48825

    Last Modified: 15 Apr 2026

    RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.

    Published: 13 Jun 2025
    9.3
    Critical

    CVE-2025-46783

    Last Modified: 15 Apr 2026

    Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product.

    Published: 13 Jun 2025
    6.9
    Medium

    CVE-2025-36506

    Last Modified: 15 Apr 2026

    External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.

    Published: 13 Jun 2025
    5.5
    Medium

    CVE-2025-6012

    Last Modified: 22 Apr 2026

    The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 13 Jun 2025
    7.2
    High

    CVE-2025-39240

    Last Modified: 15 Apr 2026

    Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.

    Published: 13 Jun 2025
    9.6
    Critical

    CVE-2024-38824

    Last Modified: 26 Feb 2026

    Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

    Published: 13 Jun 2025