9.8
    Critical

    CVE-2025-60854

    Last Modified: 6 Dec 2025

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

    Published:2 Dec 2025
    6.5
    Medium

    CVE-2025-60852

    Last Modified: 15 Apr 2026

    A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize user-controlled input before including it in CSV exports. This issue could lead to code execution on the system where the exported CSV file is opened.

    Published:23 Oct 2025
    7.5
    High

    CVE-2025-60800

    Last Modified: 6 Nov 2025

    Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

    Published:28 Oct 2025
    6.2
    Medium

    CVE-2025-60791

    Last Modified: 15 Apr 2026

    Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a failed activation attempt. The keys can be obtained by attaching a debugger or analyzing the process/memory dump and then they can be used to activate the software on the same machine without purchasing.

    Published:27 Oct 2025
    7.2
    High

    CVE-2025-60787

    Last Modified: 11 Feb 2026

    MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

    Source:prabhat
    Published:3 Oct 2025
    Unknown

    CVE-2025-60752

    https://github.com/zer0matt/CVE-2025-60752

    7.5
    High

    CVE-2025-60751

    Last Modified: 29 Apr 2026

    GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

    Source:rosario
    Published:21 Oct 2025
    7.8
    High

    CVE-2025-60749

    Last Modified: 15 Apr 2026

    DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

    Published:31 Oct 2025
    9.6
    Critical

    CVE-2025-60739

    Last Modified: 30 Dec 2025

    Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

    Published:25 Nov 2025
    9.8
    Critical

    CVE-2025-60736

    Last Modified: 5 Dec 2025

    code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

    Published:2 Dec 2025
    7
    High

    CVE-2025-60719

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published:11 Nov 2025
    7.8
    High

    CVE-2025-60710

    Last Modified: 22 Apr 2026

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

    Published:11 Nov 2025
    7.8
    High

    CVE-2025-60709

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published:11 Nov 2025
    8.8
    High

    CVE-2025-60690

    Last Modified: 4 May 2026

    A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 into a fixed-size buffer (a2) without bounds checking. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

    Source:jarrett
    Published:13 Nov 2025
    5.4
    Medium

    CVE-2025-60689

    Last Modified: 31 Aug 2026

    An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication.

    Source:jarrett
    Published:13 Nov 2025
    Unknown

    CVE-2025-60656

    https://github.com/DotAdrien/CVE-2025-60656

    Unknown

    CVE-2025-60655

    https://github.com/DotAdrien/CVE-2025-60655

    Unknown

    CVE-2025-60654

    https://github.com/DotAdrien/CVE-2025-60654

    8.2
    High

    CVE-2025-60595

    Last Modified: 15 Apr 2026

    SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.

    Published:29 Oct 2025
    7.5
    High

    CVE-2025-60574

    Last Modified: 11 Dec 2025

    A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

    Published:7 Nov 2025
    8.7
    High

    CVE-2025-60503

    Last Modified: 3 Feb 2026

    A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

    Published:3 Nov 2025
    7.2
    High

    CVE-2025-60500

    Last Modified: 17 Nov 2025

    QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

    Published:21 Oct 2025
    6.5
    Medium

    CVE-2025-60458

    Last Modified: 9 Jan 2026

    UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

    Published:29 Dec 2025
    8.6
    High

    CVE-2025-60425

    Last Modified: 5 Nov 2025

    Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

    Published:27 Oct 2025
    7.6
    High

    CVE-2025-60424

    Last Modified: 5 Nov 2025

    A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

    Published:27 Oct 2025
    Unknown

    CVE-2025-60423

    https://github.com/Zephyr1ng/CVE-2025-60423

    8.1
    High

    CVE-2025-60378

    Last Modified: 17 Nov 2025

    Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

    Published:10 Oct 2025
    7.3
    High

    CVE-2025-60375

    Last Modified: 15 Apr 2026

    The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient server-side validation. By sending empty username and password parameters in the login request, an attacker can gain unauthorized access to user accounts, including administrative accounts, without providing valid credentials.

    Published:9 Oct 2025
    6.1
    Medium

    CVE-2025-60374

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users viewing the chat, resulting in client-side code execution, potential session token theft, and other malicious actions. A different vulnerability than CVE-2024-8867.

    Published:14 Oct 2025
    8.1
    High

    CVE-2025-60357

    Last Modified: 11 Aug 2026

    AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

    Published:17 Jul 2026
    7.5
    High

    CVE-2025-60349

    Last Modified: 15 Apr 2026

    An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated.

    Published:28 Oct 2025
    7.5
    High

    CVE-2025-60188

    Last Modified: 8 Jul 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.1.

    Source:Mohammad Hossein Sadeghian
    Published:6 Nov 2025
    9.8
    Critical

    CVE-2025-60021

    Last Modified: 26 Feb 2026

    Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parameter and executes it as a command-line argument. Attackers can execute remote commands using the extra_options parameter.. Affected scenarios: Use the built-in bRPC heap profiler service to perform jemalloc memory profiling. How to Fix: we provide two methods, you can choose one of them: 1. Upgrade bRPC to version 1.15.0. 2. Apply this patch ( https://github.com/apache/brpc/pull/3101 ) manually.

    Published:16 Jan 2026
    4.6
    Medium

    CVE-2025-60013

    Last Modified: 26 Feb 2026

    When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published:15 Oct 2025
    6.3
    Medium

    CVE-2025-60012

    Last Modified: 23 Mar 2026

    Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0.8.0 when connecting to Apache Spark 3.1 or later. A request that includes a Spark configuration value supported from Apache Spark version 3.1 can lead to users gaining access to files they do not have permissions to. For the vulnerability to be exploitable, the user needs to have access to Apache Livy's REST or JDBC interface and be able to send requests with arbitrary Spark configuration values. Users are recommended to upgrade to version 0.9.0 or later, which fixes the issue.

    Published:13 Mar 2026
    9.4
    Critical

    CVE-2025-59934

    Last Modified: 15 Apr 2026

    Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the token’s signature, expiration, issuer, or audience. If an attacker learns the victim’s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victim’s password. This issue has been patched in version 4.0.1.

    Published:26 Sept 2025
    8.8
    High

    CVE-2025-59886

    Last Modified: 18 Feb 2026

    Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon retirement or end of support, there will be no new security updates, non-security updates, or paid assisted support options, or online technical content updates.

    Published:23 Dec 2025
    6.9
    Medium

    CVE-2025-59843

    Last Modified: 29 Jan 2026

    Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.2 or later to eliminate exposure. There are no workarounds for this vulnerability.

    Published:26 Sept 2025
    9.1
    Critical

    CVE-2025-59718

    Last Modified: 9 Jun 2026

    A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

    Published:9 Dec 2025
    6.4
    Medium

    CVE-2025-59712

    Last Modified: 23 Sept 2025

    Snipe-IT before 8.1.18 allows XSS.

    Published:19 Sept 2025
    8.7
    High

    CVE-2025-59536

    Last Modified: 23 Oct 2025

    Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

    Published:3 Oct 2025
    8.6
    High

    CVE-2025-59532

    Last Modified: 15 Apr 2026

    Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the intended workspace boundary and enables arbitrary file writes and command execution where the Codex process has permissions - this did not impact the network-disabled sandbox restriction. This issue has been patched in Codex CLI 0.39.0 that canonicalizes and validates that the boundary used for sandbox policy is based on where the user started the session, and not the one generated by the model. Users running 0.38.0 or earlier should update immediately via their package manager or by reinstalling the latest Codex CLI to ensure sandbox boundaries are enforced. If using the Codex IDE extension, users should immediately update to 0.4.12 for a fix of the sandbox issue.

    Published:22 Sept 2025
    10
    Critical

    CVE-2025-59528

    Last Modified: 31 Oct 2025

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.

    Source:nltt0
    Published:22 Sept 2025
    4.8
    Medium

    CVE-2025-59501

    Last Modified: 22 Feb 2026

    Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

    Published:31 Oct 2025
    7.4
    High

    CVE-2025-59489

    Last Modified: 22 Oct 2025

    Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.

    Published:3 Oct 2025
    9
    Critical

    CVE-2025-59470

    Last Modified: 26 Feb 2026

    This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

    Published:8 Jan 2026
    2.9
    Low

    CVE-2025-59427

    Last Modified: 15 Apr 2026

    The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars. This vulnerability is fixed in 1.6.0.

    Published:19 Sept 2025
    7.3
    High

    CVE-2025-59424

    Last Modified: 6 Oct 2025

    LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attacker can set a malicious JavaScript payload as their username. When an action performed by this user is recorded (e.g., generate or revoke an API token), the payload is stored in the database. The script is then executed in the browser of any user, particularly administrators, who views the /system/audit page. This vulnerability is fixed in 2.3.1.

    Published:18 Sept 2025
    Low

    CVE-2025-59396

    Last Modified: 10 Nov 2025

    Not a security vulnerability

    Published:6 Nov 2025
    9.8
    Critical

    CVE-2025-59390

    Last Modified: 11 Dec 2025

    Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-graphically secure random number generator. This may allow an attacker to predict or brute force the secret used to sign authentication cookies, potentially enabling token forgery or authentication bypass. Additionally, each process generates its own fallback secret, resulting in inconsistent secrets across nodes. This causes authentication failures in distributed or multi-broker deployments, effectively leading to a incorrectly configured clusters. Users are advised to configure a strong `druid.auth.authenticator.kerberos.cookieSignatureSecret` This issue affects Apache Druid: through 34.0.0. Users are recommended to upgrade to version 35.0.0, which fixes the issue making it mandatory to set `druid.auth.authenticator.kerberos.cookieSignatureSecret` when using the Kerberos authenticator. Services will fail to come up if the secret is not set.

    Published:26 Nov 2025
    Items Per Page