CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-13966

    Last Modified: 26 Sept 2025

    ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5252

    Last Modified: 9 Jun 2025

    A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5251

    Last Modified: 10 Jun 2025

    A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5250

    Last Modified: 10 Jun 2025

    A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    Unknown

    CVE-2025-48863

    Last Modified: 23 Dec 2025

    This CVE id was assigned but later discarded.

    Published: 27 May 2025
    Unknown

    CVE-2025-48864

    Last Modified: 23 Dec 2025

    This CVE id was assigned but later discarded.

    Published: 27 May 2025
    4.4
    Medium

    CVE-2025-23247

    Last Modified: 3 Oct 2025

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exploit of this vulnerability might lead to arbitrary code execution.

    Published: 27 May 2025
    9.3
    Critical

    CVE-2025-48057

    Last Modified: 5 Dec 2025

    Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5249

    Last Modified: 24 Jun 2025

    A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5248

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affected is an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    5.5
    Medium

    CVE-2025-27701

    Last Modified: 4 Sept 2025

    In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB Read, leading to information disclosure.

    Published: 27 May 2025
    8.4
    High

    CVE-2025-27700

    Last Modified: 26 Feb 2026

    There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 May 2025
    5.1
    Medium

    CVE-2024-56193

    Last Modified: 4 Sept 2025

    There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 27 May 2025
    2.7
    Low

    CVE-2025-48370

    Last Modified: 27 Apr 2026

    auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs. This could lead to a URL path traversal, resulting in the wrong API function being called. Implementations that follow security best practice and validate user controlled inputs, such as the userId are not affected by this. This issue has been patched in version 2.70.0.

    Published: 27 May 2025
    8.2
    High

    CVE-2025-48383

    Last Modified: 15 Apr 2026

    Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.

    Published: 27 May 2025
    2.1
    Low

    CVE-2025-2236

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue affects Advanced Authentication versions before 6.5.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5247

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The manipulation of the argument r leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    5.9
    Medium

    CVE-2025-3704

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions Volunteer Sign Up Sheets pta-volunteer-sign-up-sheets allows Stored XSS.This issue affects Volunteer Sign Up Sheets: from n/a through < 5.5.5.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5246

    Last Modified: 28 May 2025

    A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /hms/admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    4.8
    Medium

    CVE-2025-5245

    Last Modified: 12 May 2026

    A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 27 May 2025
    4.8
    Medium

    CVE-2025-5244

    Last Modified: 12 May 2026

    A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 27 May 2025
    7.3
    High

    CVE-2025-5272

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-5271

    Last Modified: 20 Apr 2026

    Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-5270

    Last Modified: 20 Apr 2026

    In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

    Published: 27 May 2025
    8.1
    High

    CVE-2025-5269

    Last Modified: 20 Apr 2026

    Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 128.11 and Thunderbird 128.11.

    Published: 27 May 2025
    8.1
    High

    CVE-2025-5268

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    4.3
    Medium

    CVE-2025-5266

    Last Modified: 20 Apr 2026

    Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-5267

    Last Modified: 20 Apr 2026

    A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    4.8
    Medium

    CVE-2025-5265

    Last Modified: 20 Apr 2026

    Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    4.8
    Medium

    CVE-2025-5264

    Last Modified: 20 Apr 2026

    Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    4.3
    Medium

    CVE-2025-5263

    Last Modified: 20 Apr 2026

    Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 115.24, Firefox ESR 128.11, Thunderbird 139, and Thunderbird 128.11.

    Published: 27 May 2025
    8.8
    High

    CVE-2025-5117

    Last Modified: 15 Apr 2026

    The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privileges to that of an administrator by creating a package post whose property_package_user_role is set to administrator and then submitting the PayPal registration form.

    Published: 27 May 2025
    4.8
    Medium

    CVE-2025-4412

    Last Modified: 15 Apr 2026

    On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted permissions for file resources apply. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission. This issue was fixed in version 1.11.5 of Viscosity.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-41653

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or become unresponsive.

    Published: 27 May 2025
    9.8
    Critical

    CVE-2025-41652

    Last Modified: 15 Apr 2026

    The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.

    Published: 27 May 2025
    9.8
    Critical

    CVE-2025-41651

    Last Modified: 15 Apr 2026

    Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-41650

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt system operations and potentially cause a denial-of-service.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-41649

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer, potentially leading to a denial-of-service condition for the devices.

    Published: 27 May 2025
    Unknown

    CVE-2025-48847

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48848

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48844

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48845

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48846

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48841

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48842

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48843

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    9.3
    Critical

    CVE-2025-2407

    Last Modified: 15 Apr 2026

    Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.

    Published: 27 May 2025
    Unknown

    CVE-2025-5242

    Last Modified: 7 Jun 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 May 2025
    5.6
    Medium

    CVE-2025-23393

    Last Modified: 15 Apr 2026

    A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows execution of arbitrary Javascript code on users machines.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3.

    Published: 27 May 2025
    5.1
    Medium

    CVE-2024-47090

    Last Modified: 3 Nov 2025

    Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

    Published: 27 May 2025