CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-0917

    Last Modified: 24 Aug 2025

    IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 11 Jun 2025
    7.5
    High

    CVE-2025-25032

    Last Modified: 24 Aug 2025

    IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted request that would exhaust memory resources.

    Published: 11 Jun 2025
    5.5
    Medium

    CVE-2025-0913

    Last Modified: 8 Aug 2025

    os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

    Published: 11 Jun 2025
    7
    High

    CVE-2025-40915

    Last Modified: 15 Apr 2026

    Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.

    Published: 11 Jun 2025
    6.8
    Medium

    CVE-2025-4673

    Last Modified: 15 Apr 2026

    Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

    Published: 11 Jun 2025
    7.5
    High

    CVE-2025-22874

    Last Modified: 15 Apr 2026

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

    Published: 11 Jun 2025
    7.2
    High

    CVE-2025-6002

    Last Modified: 15 Apr 2026

    An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.

    Published: 11 Jun 2025
    8.3
    High

    CVE-2025-6001

    Last Modified: 15 Apr 2026

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.

    Published: 11 Jun 2025
    2.4
    Low

    CVE-2025-1699

    Last Modified: 15 Apr 2026

    An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

    Published: 11 Jun 2025
    2.4
    Low

    CVE-2025-1698

    Last Modified: 15 Apr 2026

    Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.

    Published: 11 Jun 2025
    6.3
    Medium

    CVE-2025-26383

    Last Modified: 15 Apr 2026

    The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.

    Published: 11 Jun 2025
    7.3
    High

    CVE-2025-49148

    Last Modified: 15 Apr 2026

    ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system libraries like CRYPTBASE.dll and WindowsCodecs.dll from its own directory before the system path. A local, non-privileged user who can write to the folder containing clip_share.exe can place malicious DLLs there, leading to arbitrary code execution in the context of the server, and, if launched by an Administrator (or another elevated user), it results in a reliable local privilege escalation. This vulnerability is fixed in 3.8.5.

    Published: 11 Jun 2025
    7.1
    High

    CVE-2025-48447

    Last Modified: 20 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.

    Published: 11 Jun 2025
    6.5
    Medium

    CVE-2025-48448

    Last Modified: 20 Jun 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.

    Published: 11 Jun 2025
    8.8
    High

    CVE-2025-48446

    Last Modified: 16 Jun 2025

    Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.

    Published: 11 Jun 2025
    8.2
    High

    CVE-2025-49146

    Last Modified: 6 Oct 2025

    pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

    Published: 11 Jun 2025
    8.8
    High

    CVE-2025-48445

    Last Modified: 16 Jun 2025

    Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1.

    Published: 11 Jun 2025
    6.7
    Medium

    CVE-2025-3473

    Last Modified: 26 Feb 2026

    IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

    Published: 11 Jun 2025
    5.3
    Medium

    CVE-2025-0163

    Last Modified: 24 Aug 2025

    IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.

    Published: 11 Jun 2025
    5.3
    Medium

    CVE-2025-48013

    Last Modified: 20 Jun 2025

    Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

    Published: 11 Jun 2025
    5.3
    Medium

    CVE-2025-48444

    Last Modified: 20 Jun 2025

    Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

    Published: 11 Jun 2025
    9.8
    Critical

    CVE-2025-40914

    Last Modified: 15 Apr 2026

    Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

    Published: 11 Jun 2025
    6.6
    Medium

    CVE-2025-4605

    Last Modified: 19 Aug 2025

    A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49820

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49821

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49822

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49818

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49819

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49817

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49814

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49815

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    Unknown

    CVE-2025-49816

    Last Modified: 12 Jun 2025

    Not used

    Published: 11 Jun 2025
    8.1
    High

    CVE-2025-4922

    Last Modified: 22 Dec 2025

    Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.

    Published: 11 Jun 2025
    9.3
    Critical

    CVE-2025-32711

    Last Modified: 26 Feb 2026

    Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

    Published: 11 Jun 2025
    5.5
    Medium

    CVE-2025-35941

    Last Modified: 15 Apr 2026

    A password is exposed locally.

    Published: 11 Jun 2025
    6.4
    Medium

    CVE-2025-5144

    Last Modified: 21 Apr 2026

    The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Jun 2025
    9.8
    Critical

    CVE-2025-49710

    Last Modified: 20 Apr 2026

    An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.

    Published: 11 Jun 2025
    9.8
    Critical

    CVE-2025-49709

    Last Modified: 20 Apr 2026

    Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

    Published: 11 Jun 2025
    7.8
    High

    CVE-2025-5687

    Last Modified: 20 Apr 2026

    A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).

    Published: 11 Jun 2025
    7.2
    High

    CVE-2025-3302

    Last Modified: 21 Apr 2026

    The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.1.0.0.

    Published: 11 Jun 2025
    3.1
    Low

    CVE-2025-4128

    Last Modified: 8 Jul 2025

    Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.

    Published: 11 Jun 2025
    4.1
    Medium

    CVE-2025-4573

    Last Modified: 8 Jul 2025

    Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT /api/v4/ldap/groups/{remote_id}/link API when objectGUID is configured as the Group ID Attribute.

    Published: 11 Jun 2025
    8.8
    High

    CVE-2025-4315

    Last Modified: 21 Apr 2026

    The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the update_user_meta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

    Published: 11 Jun 2025
    6.8
    Medium

    CVE-2025-26412

    Last Modified: 15 Apr 2026

    The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or remote shell access to a device that interacts directly with the modem via AT commands.

    Published: 11 Jun 2025
    9.8
    Critical

    CVE-2025-41663

    Last Modified: 15 Apr 2026

    For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then executed with elevated privileges. To get into such a position, clients would need to use insecure proxy configurations.

    Published: 11 Jun 2025
    8.8
    High

    CVE-2025-41661

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.

    Published: 11 Jun 2025
    Unknown

    CVE-2025-41662

    Last Modified: 23 Jul 2025

    CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE CVE-2025-41687 has been reserved to better reflect the updated analysis.

    Published: 11 Jun 2025
    8.3
    High

    CVE-2025-29756

    Last Modified: 15 Apr 2026

    SunGrow's back end users system iSolarCloud https://isolarcloud.com  uses an MQTT service to transport data from the user's connected devices to the user's web browser.  The MQTT server however did not have sufficient restrictions in place to limit the topics that a user could subscribe to.  While the data that is transmitted through the MQTT server is encrypted and the credentials for the MQTT server are obtained though an API call, the credentials could be used to subscribe to any topic and the encryption key can be used to decrypt all messages received. An attack with an account on iSolarCloud.com could extract MQTT credentials and the decryption key from the browser and then use an external program to subscribe to the topic '#' and thus recieve all messages from all connected devices.

    Published: 11 Jun 2025
    2.1
    Low

    CVE-2025-5991

    Last Modified: 29 Jul 2026

    There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses. This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.

    Published: 11 Jun 2025
    5.2
    Medium

    CVE-2024-35295

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). The maintenance connection of affected devices fails to protect access to the device's control unit configuration. This could allow an attacker with physical access to the maintenance connection's door port to perform arbitrary configuration changes.

    Published: 11 Jun 2025