9.8
    Critical

    CVE-2025-50472

    Last Modified: 15 Apr 2026

    The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_model_meta()` function of the `ModelFileSystemCache()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized `.mdl` payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine. Note that the payload file is a hidden file, making it difficult for the victim to detect tampering. More importantly, during the model training process, after the `.mdl` file is loaded and executes arbitrary code, the normal training process remains unaffected'meaning the user remains unaware of the arbitrary code execution.

    Published:1 Aug 2025
    6.5
    Medium

    CVE-2025-50461

    Last Modified: 15 Apr 2026

    A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" backend. The script calls torch.load() with weights_only=False on user-supplied .pt files, allowing attackers to execute arbitrary code if a maliciously crafted model file is loaded. An attacker can exploit this by convincing a victim to download and place a malicious model file in a local directory with a specific filename pattern. This vulnerability may lead to arbitrary code execution with the privileges of the user running the script.

    Published:19 Aug 2025
    9.8
    Critical

    CVE-2025-50460

    Last Modified: 15 Apr 2026

    A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.load() from the PyYAML library (versions = 5.3.1). If an attacker can control the content of the YAML configuration file passed to the --run_config parameter, arbitrary code can be executed during deserialization. This can lead to full system compromise. The vulnerability is triggered when a malicious YAML file is loaded, allowing the execution of arbitrary Python commands such as os.system(). It is recommended to upgrade PyYAML to version 5.4 or higher, and to use yaml.safe_load() to mitigate the issue.

    Published:1 Aug 2025
    9.1
    Critical

    CVE-2025-50455

    Last Modified: 1 Sept 2026

    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.

    Source:Michael Chesang
    Published:27 Jul 2026
    9.8
    Critical

    CVE-2025-50433

    Last Modified: 29 Dec 2025

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

    Published:26 Nov 2025
    9.8
    Critical

    CVE-2025-50428

    Last Modified: 9 Sept 2025

    In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

    Published:27 Aug 2025
    2.9
    Low

    CVE-2025-50422

    Last Modified: 15 Apr 2026

    Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

    Published:4 Aug 2025
    6.5
    Medium

    CVE-2025-50420

    Last Modified: 9 Oct 2025

    An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

    Published:4 Aug 2025
    8.1
    High

    CVE-2025-50383

    Last Modified: 1 Oct 2025

    alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

    Published:25 Aug 2025
    Unknown

    CVE-2025-50365

    https://github.com/1h3ll/CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

    Unknown

    CVE-2025-50364

    https://github.com/1h3ll/CVE-2025-50364_CSRF_ADD_CATEGORY-phpgurukul-CVE

    5.4
    Medium

    CVE-2025-50363

    Last Modified: 5 Nov 2025

    Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

    Published:3 Nov 2025
    5.1
    Medium

    CVE-2025-50361

    Last Modified: 18 Dec 2025

    Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash.

    Published:3 Dec 2025
    8.4
    High

    CVE-2025-50360

    Last Modified: 16 Dec 2025

    A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper source file(.pr) could lead to arbitrary code execution or Denial of Service.

    Published:3 Dec 2025
    9.8
    Critical

    CVE-2025-50341

    Last Modified: 15 Apr 2026

    A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.

    Published:4 Aug 2025
    4.3
    Medium

    CVE-2025-50340

    Last Modified: 15 Apr 2026

    An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system. NOTE: this is disputed by the Supplier because the only effective way to prevent this sender spoofing is on the SMTP server, not within a client such as SOGo.

    Published:4 Aug 2025
    8.1
    High

    CVE-2025-50286

    Last Modified: 11 Aug 2025

    A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.

    Source:/bin/neko
    Published:6 Aug 2025
    7.8
    High

    CVE-2025-50168

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published:12 Aug 2025
    9.8
    Critical

    CVE-2025-50165

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

    Published:12 Aug 2025
    6.5
    Medium

    CVE-2025-50154

    Last Modified: 18 Aug 2025

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

    Source:Ruben Enkaoua
    Published:12 Aug 2025
    8.8
    High

    CVE-2025-50110

    Last Modified: 15 Apr 2026

    An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS

    Published:15 Sept 2025
    Unknown

    CVE-2025-50000

    https://github.com/adiivascu/CVE-2025-50000

    9.8
    Critical

    CVE-2025-49901

    Last Modified: 15 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.

    Published:22 Oct 2025
    10
    Critical

    CVE-2025-49844

    Last Modified: 20 Mar 2026

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

    Published:3 Oct 2025
    7
    High

    CVE-2025-49744

    Last Modified: 16 Jul 2025

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Source:nu11secur1ty
    Published:8 Jul 2025
    7.4
    High

    CVE-2025-49741

    Last Modified: 3 Aug 2025

    No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

    Source:nu11secur1ty
    Published:1 Jul 2025
    7.8
    High

    CVE-2025-49730

    Last Modified: 11 Aug 2025

    Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.

    Source:nu11secur1ty
    Published:8 Jul 2025
    6.5
    Medium

    CVE-2025-49706

    Last Modified: 26 Feb 2026

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published:8 Jul 2025
    7.8
    High

    CVE-2025-49683

    Last Modified: 3 Aug 2025

    Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.

    Source:nu11secur1ty
    Published:8 Jul 2025
    7
    High

    CVE-2025-49677

    Last Modified: 16 Jul 2025

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Source:nu11secur1ty
    Published:8 Jul 2025
    7.8
    High

    CVE-2025-49667

    Last Modified: 26 Feb 2026

    Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published:8 Jul 2025
    7.2
    High

    CVE-2025-49666

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.

    Published:8 Jul 2025
    8.5
    High

    CVE-2025-49619

    Last Modified: 15 Jun 2025

    Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).

    Source:Cristian Branet
    Published:7 Jun 2025
    9.4
    Critical

    CVE-2025-49596

    Last Modified: 15 Apr 2026

    The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

    Published:13 Jun 2025
    9.3
    Critical

    CVE-2025-49553

    Last Modified: 26 Feb 2026

    Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.

    Published:14 Oct 2025
    5.8
    Medium

    CVE-2025-49493

    Last Modified: 15 Apr 2026

    Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

    Published:30 Jun 2025
    8.7
    High

    CVE-2025-49484

    Last Modified: 22 Jul 2025

    A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.

    Source:Adam Wallwork
    Published:18 Jul 2025
    9.8
    Critical

    CVE-2025-49388

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Miraculous Core Plugin: from n/a through <= 2.0.7.

    Published:28 Aug 2025
    9.8
    Critical

    CVE-2025-49223

    Last Modified: 6 Jun 2025

    billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published:4 Jun 2025
    Unknown

    CVE-2025-49173

    https://github.com/aliyabuz25/cve-2025-49173-macos-mavericks-10.9-local-root-privesc-auth-services

    7.3
    High

    CVE-2025-49144

    Last Modified: 15 Apr 2026

    Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.

    Published:23 Jun 2025
    10
    Critical

    CVE-2025-49132

    Last Modified: 26 Jun 2025

    Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

    Source:Zen-kun04
    Published:20 Jun 2025
    6.3
    Medium

    CVE-2025-49131

    Last Modified: 29 Dec 2025

    FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a specialized, isolated environment used by FastGPT to safely execute user-submitted or dynamically generated code in isolation. The sandbox before version 4.9.11 has insufficient isolation and inadequate restrictions on code execution by allowing overly permissive syscalls, which allows attackers to escape the intended sandbox boundaries. Attackers could exploit this to read and overwrite arbitrary files and bypass Python module import restrictions. This is patched in version 4.9.11 by restricting the allowed system calls to a safer subset and additional descriptive error messaging.

    Published:9 Jun 2025
    7.5
    High

    CVE-2025-49125

    Last Modified: 3 Nov 2025

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

    Published:16 Jun 2025
    9.9
    Critical

    CVE-2025-49113

    Last Modified: 13 Jun 2025

    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

    Source:Maksim Rogov
    Published:2 Jun 2025
    8.2
    High

    CVE-2025-49091

    Last Modified: 15 Apr 2026

    KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.

    Published:11 Jun 2025
    10
    Critical

    CVE-2025-49071

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell to a Web Server.This issue affects Flozen: from n/a through < 1.5.1.

    Published:17 Jun 2025
    9.1
    Critical

    CVE-2025-49029

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <= 1.0.

    Published:1 Jul 2025
    8.2
    High

    CVE-2025-49002

    Last Modified: 5 Jun 2025

    DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

    Published:3 Jun 2025
    7.5
    High

    CVE-2025-48988

    Last Modified: 3 Nov 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

    Published:16 Jun 2025
    Items Per Page