10
    Critical

    CVE-2025-64095

    Last Modified: 3 Nov 2025

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.

    Published:28 Oct 2025
    9.8
    Critical

    CVE-2025-64087

    Last Modified: 3 Feb 2026

    A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.

    Published:20 Jan 2026
    6.1
    Medium

    CVE-2025-64027

    Last Modified: 26 Nov 2025

    Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can intercept and modify the POST /livewire/update request to inject arbitrary HTML or JavaScript into the progress_message. Because the server accepts the modified input without sanitization and reflects it back to the user, arbitrary JavaScript executes in the browser of any authenticated admin who views the import page. NOTE: this is disputed by the Supplier because the report only demonstrates that an authenticated user can choose to conduct a man-in-the-middle attack against himself.

    Published:20 Nov 2025
    7.4
    High

    CVE-2025-63946

    Last Modified: 26 Feb 2026

    A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

    Published:23 Feb 2026
    7.4
    High

    CVE-2025-63945

    Last Modified: 26 Feb 2026

    A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

    Published:23 Feb 2026
    Unknown

    CVE-2025-63943

    https://github.com/RedOpsX/CVE-2025-63943

    Unknown

    CVE-2025-63915

    https://github.com/zero-day348/CVE-2025-63915-There-is-a-Reflected-xss-vulnerability-exists-in-DoraCMS

    6.5
    Medium

    CVE-2025-63914

    Last Modified: 30 Dec 2025

    An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.

    Published:24 Nov 2025
    7.5
    High

    CVE-2025-63895

    Last Modified: 2 Jan 2026

    An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet.

    Published:10 Dec 2025
    6.8
    Medium

    CVE-2025-63892

    Last Modified: 20 Nov 2025

    A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site scripting.

    Published:18 Nov 2025
    9.8
    Critical

    CVE-2025-63888

    Last Modified: 25 Nov 2025

    The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

    Published:20 Nov 2025
    6.1
    Medium

    CVE-2025-63848

    Last Modified: 12 Dec 2025

    Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.

    Published:20 Nov 2025
    6.1
    Medium

    CVE-2025-63830

    Last Modified: 19 Nov 2025

    CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

    Published:14 Nov 2025
    Unknown

    CVE-2025-63821

    https://github.com/Xernary/CVE-2025-63821

    Unknown

    CVE-2025-63820

    https://github.com/Xernary/CVE-2025-63820

    6.1
    Medium

    CVE-2025-63735

    Last Modified: 9 Jan 2026

    A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

    Published:25 Nov 2025
    9
    Critical

    CVE-2025-63729

    Last Modified: 30 Dec 2025

    An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

    Published:25 Nov 2025
    6.1
    Medium

    CVE-2025-63708

    Last Modified: 20 Nov 2025

    Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability occurs in the webfonts API handling mechanism where font family names are not properly sanitized. An attacker can intercept fetch requests to the webfonts endpoint and inject malicious JavaScript payloads through font family names, resulting in session cookie theft, account hijacking, and unauthorized actions performed on behalf of authenticated users. The vulnerability can be exploited by injecting a fetch hook that returns controlled font data containing malicious scripts.

    Published:17 Nov 2025
    Low

    CVE-2025-63700

    Last Modified: 23 Dec 2025

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:20 Nov 2025
    7.5
    High

    CVE-2025-63667

    Last Modified: 5 Jan 2026

    Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.

    Published:12 Nov 2025
    9.8
    Critical

    CVE-2025-63666

    Last Modified: 18 Nov 2025

    Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.

    Published:12 Nov 2025
    7.3
    High

    CVE-2025-63602

    Last Modified: 31 Dec 2025

    A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lacks a properly secured DACL, allowing unprivileged users to interact with the driver and, as a result, the kernel. This can result in local privilege escalation, information disclosure, denial of service, and other unspecified impacts.

    Published:18 Nov 2025
    7.1
    High

    CVE-2025-63589

    Last Modified: 10 Nov 2025

    A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the URL path is reflected into multiple HTML elements, allowing execution of arbitrary JavaScript in victims' browsers visiting a crafted URL.

    Published:6 Nov 2025
    7.1
    High

    CVE-2025-63588

    Last Modified: 10 Nov 2025

    An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

    Published:6 Nov 2025
    Unknown

    CVE-2025-63587

    https://github.com/NRTLOX/CVE-2025-63587

    6.5
    Medium

    CVE-2025-63585

    Last Modified: 9 Jan 2026

    OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.

    Published:5 Nov 2025
    7.5
    High

    CVE-2025-63579

    Last Modified: 31 Jul 2026

    Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.

    Published:9 Jul 2026
    Unknown

    CVE-2025-63572

    https://github.com/RRespxwnss/CVE-2025-63572

    Unknown

    CVE-2025-63571

    https://github.com/RRespxwnss/CVE-2025-63571

    6.1
    Medium

    CVE-2025-63499

    Last Modified: 18 Dec 2025

    Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

    Published:4 Dec 2025
    6.1
    Medium

    CVE-2025-63498

    Last Modified: 30 Dec 2025

    alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

    Published:24 Nov 2025
    7.3
    High

    CVE-2025-63441

    Last Modified: 4 Feb 2026

    Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

    Published:3 Nov 2025
    4.1
    Medium

    CVE-2025-63420

    Last Modified: 5 Feb 2026

    CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent HTML execution in admin sessions.

    Published:7 Nov 2025
    6.1
    Medium

    CVE-2025-63419

    Last Modified: 31 Dec 2025

    Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.

    Published:12 Nov 2025
    5.1
    Medium

    CVE-2025-63408

    Last Modified: 31 Dec 2025

    Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands.

    Published:18 Nov 2025
    8.8
    High

    CVE-2025-63406

    Last Modified: 9 Jan 2026

    An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php

    Published:13 Nov 2025
    9.8
    Critical

    CVE-2025-63353

    Last Modified: 31 Dec 2025

    A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe the SSID to predict the default password without authentication or user interaction.

    Published:12 Nov 2025
    9.8
    Critical

    CVE-2025-63334

    Last Modified: 9 Jan 2026

    PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands with root privileges on the underlying system.

    Published:5 Nov 2025
    10
    Critical

    CVE-2025-63314

    Last Modified: 22 Jan 2026

    A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

    Published:12 Jan 2026
    8.1
    High

    CVE-2025-63307

    Last Modified: 8 Dec 2025

    alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

    Published:6 Nov 2025
    8.2
    High

    CVE-2025-63298

    Last Modified: 6 Nov 2025

    A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request, enabling the deletion of arbitrary files on the web server or underlying operating system.

    Published:30 Oct 2025
    6.5
    Medium

    CVE-2025-63296

    Last Modified: 5 Feb 2026

    KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

    Published:10 Nov 2025
    4.3
    Medium

    CVE-2025-62950

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Cross Site Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.0.0.

    Published:6 Nov 2025
    9.9
    Critical

    CVE-2025-62878

    Last Modified: 15 Apr 2026

    A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

    Published:25 Feb 2026
    9.1
    Critical

    CVE-2025-62821

    Last Modified: 22 Jun 2026

    Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.

    Published:19 Jun 2026
    7.5
    High

    CVE-2025-62727

    Last Modified: 15 Apr 2026

    Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.

    Published:28 Oct 2025
    8.8
    High

    CVE-2025-62726

    Last Modified: 31 Dec 2025

    n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository containing a pre-commit hook, the subsequent use of the Commit operation in the Git Node can inadvertently trigger the hook’s execution. This allows attackers to execute arbitrary code within the n8n environment, potentially compromising the system and any connected credentials or workflows. This vulnerability is fixed in 1.113.0.

    Published:30 Oct 2025
    6.4
    Medium

    CVE-2025-62676

    Last Modified: 26 Feb 2026

    An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.

    Published:10 Feb 2026
    8.2
    High

    CVE-2025-62641

    Last Modified: 26 Feb 2026

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

    Published:21 Oct 2025
    Low

    CVE-2025-62639

    Last Modified: 29 Apr 2026

    Not used

    Source:Cristian Branet
    Published:17 Oct 2025
    Items Per Page