8.8
    High

    CVE-2025-47181

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

    Published:22 May 2025
    8
    High

    CVE-2025-47178

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.

    Published:8 Jul 2025
    7.8
    High

    CVE-2025-47176

    Last Modified: 26 Feb 2026

    '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

    Published:10 Jun 2025
    7.8
    High

    CVE-2025-47175

    Last Modified: 8 Jul 2025

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Source:Mohammed Idrees Banyamer
    Published:10 Jun 2025
    6.7
    Medium

    CVE-2025-47171

    Last Modified: 16 Jul 2025

    Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

    Source:nu11secur1ty
    Published:10 Jun 2025
    8.8
    High

    CVE-2025-47166

    Last Modified: 2 Jul 2025

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Source:nu11secur1ty
    Published:10 Jun 2025
    7.8
    High

    CVE-2025-47165

    Last Modified: 26 Jun 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Source:nu11secur1ty
    Published:10 Jun 2025
    7.8
    High

    CVE-2025-47161

    Last Modified: 8 Jul 2025

    Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

    Source:Rich Mirch
    Published:15 May 2025
    5.4
    Medium

    CVE-2025-47029

    Last Modified: 24 Jun 2025

    Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published:10 Jun 2025
    7.7
    High

    CVE-2025-46822

    Last Modified: 25 May 2025

    OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.

    Source:d3sca
    Published:21 May 2025
    7.1
    High

    CVE-2025-46820

    Last Modified: 15 Apr 2026

    phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom workflow run artifact. The ci.yml workflow file uses actions/upload-artifact@v4 to upload the build artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's GITHUB_TOKEN. Seeing as the artifact can be downloaded prior to the end of the workflow, there is a few seconds where an attacker can extract the token from the artifact and use it with the GitHub API to push malicious code or rewrite release commits in your repository. Any downstream user of the repository may be affected, but the token should only be valid for the duration of the workflow run, limiting the time during which exploitation could occur. Version 4.1.8 fixes the issue.

    Published:6 May 2025
    6.3
    Medium

    CVE-2025-46819

    Last Modified: 27 Jan 2026

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA script to read out-of-bound data or crash the server and subsequent denial of service. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to block a script by restricting both the EVAL and FUNCTION command families.

    Published:3 Oct 2025
    6
    Medium

    CVE-2025-46818

    Last Modified: 27 Jan 2026

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate different LUA objects and potentially run their own code in the context of another user. The problem exists in all versions of Redis with LUA scripting. This issue is fixed in version 8.2.2. A workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing LUA scripts. This can be done using ACL to block a script by restricting both the EVAL and FUNCTION command families.

    Published:3 Oct 2025
    7
    High

    CVE-2025-46817

    Last Modified: 27 Jan 2026

    Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2.

    Published:3 Oct 2025
    9.4
    Critical

    CVE-2025-46816

    Last Modified: 15 Apr 2026

    goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible for anyone to execute commands on the server. The function `dispatchReadPump` does not checks the option cli `-c`, thus allowing anyone to execute arbitrary command through the use of websockets. Version 1.0.5 fixes the issue.

    Published:6 May 2025
    9.3
    Critical

    CVE-2025-46811

    Last Modified: 30 Apr 2026

    A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.87-150400.3.110.2; SUSE Manager Server Module 4.3: from ? before 4.3.87-150400.3.110.2.

    Source:wjmaj98
    Published:30 Jul 2025
    7.3
    High

    CVE-2025-46731

    Last Modified: 3 Sept 2025

    Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

    Published:5 May 2025
    6
    Medium

    CVE-2025-46721

    Last Modified: 23 Jun 2025

    nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the target site, or on a subdomain of the target site (either via XSS, or otherwise) to bypass CSRF checks and issue requests on user's behalf. Due to misuse of the Go `net/http` library, nosurf categorizes all incoming requests as plain-text HTTP requests, in which case the `Referer` header is not checked to have the same origin as the target webpage. If the attacker has control over HTML contents on either the target website (e.g. `example.com`), or on a website hosted on a subdomain of the target (e.g. `attacker.example.com`), they will also be able to manipulate cookies set for the target website. By acquiring the secret CSRF token from the cookie, or overriding the cookie with a new token known to the attacker, `attacker.example.com` is able to craft cross-site requests to `example.com`. A patch for the issue was released in nosurf 1.2.0. In lieu of upgrading to a patched version of nosurf, users may additionally use another HTTP middleware to ensure that a non-safe HTTP request is coming from the same origin (e.g. by requiring a `Sec-Fetch-Site: same-origin` header in the request).

    Published:13 May 2025
    7.3
    High

    CVE-2025-46701

    Last Modified: 3 Nov 2025

    Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.

    Published:29 May 2025
    7.2
    High

    CVE-2025-46657

    Last Modified: 12 May 2025

    Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

    Published:27 Apr 2025
    9.8
    Critical

    CVE-2025-46408

    Last Modified: 17 Oct 2025

    An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.

    Published:15 Sept 2025
    8.6
    High

    CVE-2025-46359

    Last Modified: 6 Aug 2025

    A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by restoring a crafted backup file.

    Published:31 Jul 2025
    9.8
    Critical

    CVE-2025-46295

    Last Modified: 26 Feb 2026

    Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4.

    Published:16 Dec 2025
    9.3
    Critical

    CVE-2025-46271

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

    Published:24 Apr 2025
    6.5
    Medium

    CVE-2025-46206

    Last Modified: 2 Oct 2025

    An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

    Published:4 Aug 2025
    6.5
    Medium

    CVE-2025-46204

    Last Modified: 10 Jun 2025

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.

    Published:4 Jun 2025
    6.5
    Medium

    CVE-2025-46203

    Last Modified: 10 Jun 2025

    An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

    Published:4 Jun 2025
    Unknown

    CVE-2025-46181

    https://github.com/shemkumar/CVE-2025-46181-XSS

    6.1
    Medium

    CVE-2025-46178

    Last Modified: 2 Jul 2025

    Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.

    Published:9 Jun 2025
    6.1
    Medium

    CVE-2025-46173

    Last Modified: 10 Jun 2025

    code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.

    Published:27 May 2025
    5.4
    Medium

    CVE-2025-46171

    Last Modified: 28 Jul 2025

    vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

    Published:23 Jul 2025
    9.9
    Critical

    CVE-2025-46157

    Last Modified: 26 Jun 2025

    An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

    Published:18 Jun 2025
    Unknown

    CVE-2025-46142

    https://github.com/AugustusSploits/CVE-2025-46142

    7.1
    High

    CVE-2025-46099

    Last Modified: 14 Oct 2025

    In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

    Published:23 Jul 2025
    5.3
    Medium

    CVE-2025-46080

    Last Modified: 4 Jun 2025

    HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.

    Published:29 May 2025
    5.3
    Medium

    CVE-2025-46078

    Last Modified: 4 Jun 2025

    HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

    Published:29 May 2025
    6.5
    Medium

    CVE-2025-46047

    Last Modified: 4 Sept 2025

    A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.

    Published:2 Sept 2025
    5.4
    Medium

    CVE-2025-46041

    Last Modified: 15 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).

    Source:/bin/neko
    Published:9 Jun 2025
    5.4
    Medium

    CVE-2025-46018

    Last Modified: 14 Oct 2025

    CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.

    Published:1 Aug 2025
    6.1
    Medium

    CVE-2025-45960

    Last Modified: 14 Oct 2025

    Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding

    Published:25 Jul 2025
    Unknown

    CVE-2025-45955

    https://github.com/surendrapuppala7/CVE-2025-45955

    5.4
    Medium

    CVE-2025-45809

    Last Modified: 12 Mar 2026

    SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

    Published:3 Jul 2025
    7.6
    High

    CVE-2025-45805

    Last Modified: 16 Dec 2025

    In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

    Published:3 Sept 2025
    Unknown

    CVE-2025-45781

    https://github.com/ahmetumitbayram/CVE-2025-45781-Kemal-Framework-Path-Traversal-Vulnerability-PoC

    6.1
    Medium

    CVE-2025-45778

    Last Modified: 1 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description text field.

    Published:1 Aug 2025
    Unknown

    CVE-2025-45710

    https://github.com/partywavesec/CVE-2025-45710

    8.1
    High

    CVE-2025-45620

    Last Modified: 6 Aug 2025

    An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request

    Published:30 Jul 2025
    6.5
    Medium

    CVE-2025-45619

    Last Modified: 6 Aug 2025

    An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function

    Published:30 Jul 2025
    7.3
    High

    CVE-2025-45542

    Last Modified: 5 Jun 2025

    SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.

    Source:Sanjay Singh
    Published:2 Jun 2025
    6.5
    Medium

    CVE-2025-45512

    Last Modified: 2 Oct 2025

    A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.

    Published:5 Aug 2025
    Items Per Page