7.1
    High

    CVE-2025-56219

    Last Modified: 27 Oct 2025

    Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created.

    Published:20 Oct 2025
    9.8
    Critical

    CVE-2025-56218

    Last Modified: 27 Oct 2025

    An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

    Published:17 Oct 2025
    7.3
    High

    CVE-2025-56132

    Last Modified: 15 Oct 2025

    LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based lockout mechanisms to mitigate brute-force attacks, user enumeration remains possible by default. In versions prior to 4.2, no such user-level protection is in place, only basic IP-based rate limiting is enforced. This IP-based protection can be bypassed by distributing requests across multiple IPs (e.g., rotating IP or proxies). Effectively bypassing both login and password reset security controls. Successful exploitation allows an attacker to enumerate valid email addresses registered for the application, increasing the risk of follow-up attacks such as password spraying.

    Published:30 Sept 2025
    6.5
    Medium

    CVE-2025-56019

    Last Modified: 27 Oct 2025

    An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without authentication. Once an unauthorized connection is established, legitimate applications are unable to connect, causing a denial of service. The attack requires proximity to the device, making it exploitable from an adjacent network location.

    Published:2 Oct 2025
    7.5
    High

    CVE-2025-56015

    Last Modified: 13 Apr 2026

    In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.

    Published:7 Apr 2026
    9.8
    Critical

    CVE-2025-56005

    Last Modified: 6 Feb 2026

    An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows execution of embedded code via `__reduce__()`, an attacker can achieve code execution by passing a malicious pickle file. The parameter is not mentioned in official documentation or the GitHub repository, yet it is active in the PyPI version. This introduces a stealthy backdoor and persistence risk. NOTE: A third-party states that this vulnerability should be rejected because the proof of concept does not demonstrate arbitrary code execution and fails to complete successfully.

    Published:20 Jan 2026
    8.1
    High

    CVE-2025-55998

    Last Modified: 29 Sept 2025

    A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter

    Published:8 Sept 2025
    6.3
    Medium

    CVE-2025-55996

    Last Modified: 16 Oct 2025

    Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface

    Published:12 Sept 2025
    7.5
    High

    CVE-2025-55972

    Last Modified: 16 Oct 2025

    A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.

    Published:3 Oct 2025
    4.7
    Medium

    CVE-2025-55971

    Last Modified: 15 Oct 2025

    TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over TCP/16398 and attempts to retrieve externally referenced URIs, including attacker-controlled payloads. The blind SSRF allows for sending requests on behalf of the TV, which can be leveraged to probe for other internal or external services accessible by the device (e.g., 127.0.0.1:16XXX, LAN services, or internet targets), potentially enabling additional exploit chains.

    Published:3 Oct 2025
    7.3
    High

    CVE-2025-55912

    Last Modified: 16 Sept 2025

    An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

    Source:Mukundsinh Solanki (r00td3str0y3r)
    Published:18 Sept 2025
    6.5
    Medium

    CVE-2025-55911

    Last Modified: 16 Sept 2025

    An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter

    Source:Mukundsinh Solanki (r00td3str0y3r)
    Published:18 Sept 2025
    8.3
    High

    CVE-2025-55903

    Last Modified: 15 Apr 2026

    A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

    Published:10 Oct 2025
    Unknown

    CVE-2025-55891

    https://github.com/terribledactyl/CVE-2025-55891

    7.3
    High

    CVE-2025-55888

    Last Modified: 14 Oct 2025

    Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions.

    Published:22 Sept 2025
    6.1
    Medium

    CVE-2025-55887

    Last Modified: 14 Oct 2025

    Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim.

    Published:22 Sept 2025
    6.5
    Medium

    CVE-2025-55886

    Last Modified: 15 Apr 2026

    An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

    Published:22 Sept 2025
    6.3
    Medium

    CVE-2025-55885

    Last Modified: 14 Oct 2025

    SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php

    Published:22 Sept 2025
    Unknown

    CVE-2025-55854

    https://github.com/PushkarAyengar/CVE-2025-55854-PoC

    9.1
    Critical

    CVE-2025-55853

    Last Modified: 25 Mar 2026

    SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI).

    Published:19 Feb 2026
    Unknown

    CVE-2025-55817

    https://github.com/5qu1n7/CVE-2025-55817

    6.1
    Medium

    CVE-2025-55816

    Last Modified: 15 Dec 2025

    HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

    Published:11 Dec 2025
    7.5
    High

    CVE-2025-55780

    Last Modified: 8 Oct 2025

    A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.

    Published:23 Sept 2025
    7.5
    High

    CVE-2025-55763

    Last Modified: 9 Sept 2025

    Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

    Published:29 Aug 2025
    7.5
    High

    CVE-2025-55752

    Last Modified: 12 May 2026

    Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

    Published:27 Oct 2025
    9.3
    Critical

    CVE-2025-55746

    Last Modified: 13 Jan 2026

    Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3.

    Published:20 Aug 2025
    6.5
    Medium

    CVE-2025-55668

    Last Modified: 4 Nov 2025

    Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

    Published:13 Aug 2025
    Unknown

    CVE-2025-55616

    https://github.com/livepwn/CVE-2025-55616

    5.4
    Medium

    CVE-2025-55580

    Last Modified: 9 Sept 2025

    SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8.

    Published:29 Aug 2025
    5.4
    Medium

    CVE-2025-55579

    Last Modified: 9 Sept 2025

    SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

    Published:29 Aug 2025
    9.8
    Critical

    CVE-2025-55575

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

    Published:25 Aug 2025
    Unknown

    CVE-2025-55555

    https://github.com/aydin5245/CVE-2025-55555-CVE

    6.5
    Medium

    CVE-2025-55462

    Last Modified: 5 Feb 2026

    A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious third-party websites to perform authenticated cross-origin requests against the Eramba API, including endpoints like /system-api/login and /system-api/user/me. The response includes sensitive user session data (ID, name, email, access groups), which is accessible to the attacker's JavaScript. This flaw enables full session hijack and data exfiltration without user interaction. Eramba versions 3.23.3 and earlier were tested and appear unaffected. The vulnerability is present in default installations, requiring no custom configuration.

    Published:13 Jan 2026
    7.3
    High

    CVE-2025-55449

    Last Modified: 12 May 2026

    AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

    Published:8 May 2026
    9.8
    Critical

    CVE-2025-55423

    Last Modified: 30 Jan 2026

    A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

    Published:20 Jan 2026
    Unknown

    CVE-2025-55349

    https://github.com/GoldenTicketLabs/CVE-2025-55349

    6.8
    Medium

    CVE-2025-55320

    Last Modified: 22 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.

    Published:14 Oct 2025
    8.8
    High

    CVE-2025-55319

    Last Modified: 26 Feb 2026

    Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

    Published:12 Sept 2025
    9.9
    Critical

    CVE-2025-55315

    Last Modified: 6 Apr 2026

    Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

    Source:Mohammed Idrees Banyamer
    Published:14 Oct 2025
    5.4
    Medium

    CVE-2025-55287

    Last Modified: 3 Sept 2025

    Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session, leading to session hijacking, data theft, and UI manipulation. This vulnerability is fixed in 4.4.0.

    Published:18 Aug 2025
    10
    Critical

    CVE-2025-55241

    Last Modified: 26 Feb 2026

    Azure Entra ID Elevation of Privilege Vulnerability

    Published:4 Sept 2025
    8.8
    High

    CVE-2025-55234

    Last Modified: 26 Feb 2026

    SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks: Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server Hardening—SMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures.

    Published:9 Sept 2025
    6.7
    Medium

    CVE-2025-55226

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.

    Published:9 Sept 2025
    3.6
    Low

    CVE-2025-55188

    Last Modified: 4 Nov 2025

    7-Zip before 25.01 does not always properly handle symbolic links during extraction.

    Published:8 Aug 2025
    7.5
    High

    CVE-2025-55184

    Last Modified: 15 Dec 2025

    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

    Published:11 Dec 2025
    5.3
    Medium

    CVE-2025-55183

    Last Modified: 7 Jan 2026

    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.

    Published:11 Dec 2025
    10
    Critical

    CVE-2025-55182

    Last Modified: 9 Apr 2026

    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

    Source:danieljavanrad
    Published:3 Dec 2025
    5.4
    Medium

    CVE-2025-55177

    Last Modified: 26 Feb 2026

    Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

    Published:29 Aug 2025
    8.2
    High

    CVE-2025-55163

    Last Modified: 4 Nov 2025

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.

    Published:13 Aug 2025
    9.1
    Critical

    CVE-2025-55130

    Last Modified: 26 Feb 2026

    A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

    Published:20 Jan 2026
    Items Per Page