1.2
    Low

    CVE-2025-59382

    Last Modified: 12 Jun 2026

    QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

    Published:10 Jun 2026
    3.7
    Low

    CVE-2025-59376

    Last Modified: 20 Sept 2025

    feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete operation.

    Published:15 Sept 2025
    9.3
    Critical

    CVE-2025-59367

    Last Modified: 26 Feb 2026

    An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.

    Published:13 Nov 2025
    9.8
    Critical

    CVE-2025-59359

    Last Modified: 14 Oct 2025

    The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

    Published:15 Sept 2025
    5.5
    Medium

    CVE-2025-59342

    Last Modified: 16 Dec 2025

    esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the handling of the X-Zone-Id HTTP header allows an attacker to cause the application to write files outside the intended storage location. The header value is used to build a filesystem path but is not properly canonicalized or restricted to the application’s storage base directory. As a result, supplying ../ sequences in X-Zone-Id causes files to be written to arbitrary directories. Version 136.1 contains a patch.

    Source:Byte Reaper
    Published:17 Sept 2025
    9.8
    Critical

    CVE-2025-59287

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

    Published:14 Oct 2025
    7
    High

    CVE-2025-59285

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

    Published:14 Oct 2025
    3.3
    Low

    CVE-2025-59284

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

    Published:14 Oct 2025
    7.8
    High

    CVE-2025-59254

    Last Modified: 6 Apr 2026

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Source:nu11secur1ty
    Published:14 Oct 2025
    5.5
    Medium

    CVE-2025-59253

    Last Modified: 22 Feb 2026

    Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

    Published:14 Oct 2025
    9.8
    Critical

    CVE-2025-59246

    Last Modified: 26 Feb 2026

    Azure Entra ID Elevation of Privilege Vulnerability

    Published:9 Oct 2025
    7.8
    High

    CVE-2025-59230

    Last Modified: 26 Feb 2026

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published:14 Oct 2025
    8.8
    High

    CVE-2025-59213

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.

    Published:14 Oct 2025
    7
    High

    CVE-2025-59194

    Last Modified: 22 Feb 2026

    Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published:14 Oct 2025
    5.3
    Medium

    CVE-2025-59139

    Last Modified: 17 Sept 2025

    Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the `Content-Length` header even when a `Transfer-Encoding: chunked` header was also included. According to the HTTP specification, `Content-Length` must be ignored in such cases. This discrepancy could allow oversized request bodies to bypass the configured limit. Most standards-compliant runtimes and reverse proxies may reject such malformed requests with `400 Bad Request`, so the practical impact depends on the runtime and deployment environment. If body size limits are used as a safeguard against large or malicious requests, this flaw could allow attackers to send oversized request bodies. The primary risk is denial of service (DoS) due to excessive memory or CPU consumption when handling very large requests. The implementation has been updated to align with the HTTP specification, ensuring that `Transfer-Encoding` takes precedence over `Content-Length`. The issue is fixed in Hono v4.9.7, and all users should upgrade immediately.

    Published:12 Sept 2025
    7.3
    High

    CVE-2025-59118

    Last Modified: 13 Nov 2025

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue.

    Published:12 Nov 2025
    9.8
    Critical

    CVE-2025-59059

    Last Modified: 5 Mar 2026

    Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

    Published:3 Mar 2026
    7.6
    High

    CVE-2025-59057

    Last Modified: 30 Jan 2026

    React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.

    Published:10 Jan 2026
    7.6
    High

    CVE-2025-58789

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.

    Published:5 Sept 2025
    7.6
    High

    CVE-2025-58788

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.

    Published:5 Sept 2025
    7.2
    High

    CVE-2025-58780

    Last Modified: 15 Apr 2026

    index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnerability."

    Published:5 Sept 2025
    7.5
    High

    CVE-2025-58726

    Last Modified: 26 Feb 2026

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published:14 Oct 2025
    8.8
    High

    CVE-2025-58718

    Last Modified: 26 Feb 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published:14 Oct 2025
    9.9
    Critical

    CVE-2025-58443

    Last Modified: 29 Sept 2025

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be released 9/15/2025. To address this vulnerability immediately, upgrade to the latest version of either the dev-branch or working-1.6 branch. This will patch the issue for users concerned about immediate exposure. See the FOG Project documentation for step-by-step upgrade instructions: https://docs.fogproject.org/en/latest/install-fog-server#choosing-a-fog-version.

    Published:6 Sept 2025
    Low

    CVE-2025-58440

    Last Modified: 5 Sept 2025

    The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.

    Published:1 Sept 2025
    9.8
    Critical

    CVE-2025-58434

    Last Modified: 13 May 2026

    Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO). This vulnerability applies to both the cloud service (`cloud.flowiseai.com`) and self-hosted/local Flowise deployments that expose the same API. Commit 9e178d68873eb876073846433a596590d3d9c863 in version 3.0.6 secures password reset endpoints. Several recommended remediation steps are available. Do not return reset tokens or sensitive account details in API responses. Tokens must only be delivered securely via the registered email channel. Ensure `forgot-password` responds with a generic success message regardless of input, to avoid user enumeration. Require strong validation of the `tempToken` (e.g., single-use, short expiry, tied to request origin, validated against email delivery). Apply the same fixes to both cloud and self-hosted/local deployments. Log and monitor password reset requests for suspicious activity. Consider multi-factor verification for sensitive accounts.

    Source:andersoncezar048
    Published:12 Sept 2025
    9.9
    Critical

    CVE-2025-58371

    Last Modified: 15 Sept 2025

    Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request metadata in a privileged context, allowing an attacker to craft malicious input and achieve Remote Code Execution (RCE) on the Actions runner. The workflow runs with broad permissions and access to repository secrets. It is possible for an attacker to execute arbitrary commands on the runner, push or modify code in the repository, access secrets, and create malicious releases or packages, resulting in a complete compromise of the repository and its associated services. This is fixed in version 3.26.7.

    Published:5 Sept 2025
    8.2
    High

    CVE-2025-58360

    Last Modified: 26 Feb 2026

    GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.

    Published:25 Nov 2025
    7.5
    High

    CVE-2025-58180

    Last Modified: 4 Feb 2026

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered. If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact. The vulnerability is patched in version 1.11.3. As a workaround, OctoPrint administrators who have event handlers configured that include any kind of filename based placeholders should disable those by setting their `enabled` property to `False` or unchecking the "Enabled" checkbox in the GUI based Event Manager. Alternatively, OctoPrint administrators should set `feature.enforceReallyUniversalFilenames` to `true` in `config.yaml` and restart OctoPrint, then vet the existing uploads and make sure to delete any suspicious looking files. As always, OctoPrint administrators are advised to not expose OctoPrint on hostile networks like the public internet, and to vet who has access to their instance.

    Source:prabhat
    Published:9 Sept 2025
    7.2
    High

    CVE-2025-58179

    Last Modified: 22 Dec 2025

    Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs it receives, allowing content from unauthorized third-party domains to be served. a A bug in impacted versions of the @astrojs/cloudflare adapter for deployment on Cloudflare’s infrastructure, allows an attacker to bypass the third-party domain restrictions and serve any content from the vulnerable origin. This issue is fixed in version 12.6.6.

    Published:4 Sept 2025
    8.3
    High

    CVE-2025-58098

    Last Modified: 26 Feb 2026

    Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

    Published:5 Dec 2025
    8
    High

    CVE-2025-58060

    Last Modified: 4 Nov 2025

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.

    Published:11 Sept 2025
    6.7
    Medium

    CVE-2025-58034

    Last Modified: 26 Feb 2026

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

    Published:18 Nov 2025
    6.5
    Medium

    CVE-2025-57926

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.

    Published:22 Sept 2025
    10
    Critical

    CVE-2025-57870

    Last Modified: 26 Feb 2026

    A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

    Published:22 Oct 2025
    7.1
    High

    CVE-2025-57833

    Last Modified: 4 Nov 2025

    An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

    Published:3 Sept 2025
    10
    Critical

    CVE-2025-57819

    Last Modified: 3 Sept 2026

    FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

    Source:Jared Brits
    Published:28 Aug 2025
    8.2
    High

    CVE-2025-57773

    Last Modified: 3 Sept 2025

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar. The vulnerability has been fixed in version 2.10.12.

    Published:25 Aug 2025
    7.2
    High

    CVE-2025-57642

    Last Modified: 16 Sept 2025

    A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.

    Source:Debug Security
    Published:10 Sept 2025
    Unknown

    CVE-2025-57617

    https://github.com/Gooseinpants/Dashy-auth-bypass

    5.4
    Medium

    CVE-2025-57576

    Last Modified: 10 Sept 2025

    PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.

    Published:4 Sept 2025
    9.8
    Critical

    CVE-2025-57529

    Last Modified: 10 Feb 2026

    YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could lead to unauthorized data access

    Published:3 Feb 2026
    6.1
    Medium

    CVE-2025-57520

    Last Modified: 16 Sept 2025

    A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.

    Published:10 Sept 2025
    9.8
    Critical

    CVE-2025-57515

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution of time-delay functions to infer database responses.

    Published:6 Oct 2025
    8.1
    High

    CVE-2025-57489

    Last Modified: 5 Dec 2025

    Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.

    Published:1 Dec 2025
    8.1
    High

    CVE-2025-57483

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.

    Published:29 Sept 2025
    6.1
    Medium

    CVE-2025-57462

    Last Modified: 31 Dec 2025

    Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.

    Published:29 Dec 2025
    9.8
    Critical

    CVE-2025-57460

    Last Modified: 31 Dec 2025

    File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

    Published:29 Dec 2025
    Unknown

    CVE-2025-57459

    https://github.com/aljoharasubaie/CVE-2025-57459

    8.8
    High

    CVE-2025-57457

    Last Modified: 15 Apr 2026

    An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.

    Published:8 Oct 2025
    Items Per Page