7.1
    High

    CVE-2025-45467

    Last Modified: 12 Jan 2026

    Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.

    Published:25 Jul 2025
    8.8
    High

    CVE-2025-45466

    Last Modified: 12 Jan 2026

    Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.

    Published:25 Jul 2025
    8.1
    High

    CVE-2025-45422

    Last Modified: 3 Aug 2026

    Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.

    Published:9 Jul 2026
    Unknown

    CVE-2025-45407

    https://github.com/yallasec/CVE-2025-45407

    8.1
    High

    CVE-2025-45346

    Last Modified: 6 Aug 2025

    SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.

    Published:29 Jul 2025
    5.5
    Medium

    CVE-2025-45250

    Last Modified: 27 Jun 2025

    MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

    Published:6 May 2025
    6.1
    Medium

    CVE-2025-44998

    Last Modified: 31 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

    Published:23 May 2025
    9.9
    Critical

    CVE-2025-44823

    Last Modified: 6 Nov 2025

    Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.

    Published:7 Oct 2025
    Unknown

    CVE-2025-44810

    https://github.com/gduma-phData/patch-CVE-2025-44810

    6.5
    Medium

    CVE-2025-44608

    Last Modified: 7 Aug 2025

    CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.

    Published:25 Jul 2025
    Unknown

    CVE-2025-44603

    https://github.com/Moulish2004/CVE-2025-44603-CSRF-Leads_to_Create_FakeUsers

    7.5
    High

    CVE-2025-44203

    Last Modified: 9 Jul 2026

    In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.

    Published:20 Jun 2025
    8.2
    High

    CVE-2025-44177

    Last Modified: 16 Jul 2025

    A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences.

    Source:Imraan Khan (Lich-Sec)
    Published:9 Jul 2025
    9.8
    Critical

    CVE-2025-44148

    Last Modified: 9 Jun 2025

    Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

    Published:3 Jun 2025
    8.2
    High

    CVE-2025-44137

    Last Modified: 20 Jan 2026

    MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web server. Affected GET parameters are "TileMatrix", "TileRow", "TileCol" and "Format"

    Published:29 Jul 2025
    9.8
    Critical

    CVE-2025-44136

    Last Modified: 6 Aug 2025

    MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

    Published:29 Jul 2025
    4.8
    Medium

    CVE-2025-44108

    Last Modified: 12 Jun 2025

    A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.

    Published:19 May 2025
    5.1
    Medium

    CVE-2025-44039

    Last Modified: 11 Jul 2025

    CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.

    Published:13 May 2025
    7.3
    High

    CVE-2025-43990

    Last Modified: 26 Feb 2026

    Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published:5 Nov 2025
    8.6
    High

    CVE-2025-43960

    Last Modified: 12 Sept 2025

    Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.

    Published:25 Aug 2025
    4.1
    Medium

    CVE-2025-43929

    Last Modified: 24 Apr 2025

    open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

    Published:20 Apr 2025
    5.3
    Medium

    CVE-2025-43921

    Last Modified: 28 Apr 2025

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

    Published:20 Apr 2025
    5.4
    Medium

    CVE-2025-43920

    Last Modified: 28 Apr 2025

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

    Published:20 Apr 2025
    5.8
    Medium

    CVE-2025-43919

    Last Modified: 28 Apr 2025

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

    Published:20 Apr 2025
    8.2
    High

    CVE-2025-43865

    Last Modified: 15 Apr 2026

    React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.

    Published:25 Apr 2025
    7.5
    High

    CVE-2025-43864

    Last Modified: 15 Apr 2026

    React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application. This issue has been patched in version 7.5.2.

    Published:25 Apr 2025
    9.1
    Critical

    CVE-2025-43564

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed

    Published:13 May 2025
    4.3
    Medium

    CVE-2025-43541

    Last Modified: 22 Apr 2026

    A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published:17 Dec 2025
    5.5
    Medium

    CVE-2025-43537

    Last Modified: 22 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.

    Published:11 Feb 2026
    8.8
    High

    CVE-2025-43529

    Last Modified: 22 Apr 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

    Published:16 Dec 2025
    4.9
    Medium

    CVE-2025-43504

    Last Modified: 22 Apr 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.

    Published:4 Nov 2025
    5.5
    Medium

    CVE-2025-43426

    Last Modified: 2 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published:4 Nov 2025
    7.8
    High

    CVE-2025-43407

    Last Modified: 11 Jun 2026

    This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. An app may be able to break out of its sandbox.

    Published:4 Nov 2025
    6.3
    Medium

    CVE-2025-43400

    Last Modified: 18 Jun 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory.

    Published:29 Sept 2025
    6.5
    Medium

    CVE-2025-43372

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published:15 Sept 2025
    10
    Critical

    CVE-2025-43300

    Last Modified: 31 Aug 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

    Published:21 Aug 2025
    9.9
    Critical

    CVE-2025-42957

    Last Modified: 15 Apr 2026

    SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

    Published:12 Aug 2025
    10
    Critical

    CVE-2025-42944

    Last Modified: 15 Apr 2026

    Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high impact to the application's confidentiality, integrity, and availability.

    Published:9 Sept 2025
    Unknown

    CVE-2025-42558

    https://github.com/gduma-phData/patch-CVE-2025-42558

    10
    Critical

    CVE-2025-41656

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.

    Published:1 Jul 2025
    9.8
    Critical

    CVE-2025-41646

    Last Modified: 10 Jun 2025

    An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

    Published:6 Jun 2025
    8.7
    High

    CVE-2025-41373

    Last Modified: 3 Aug 2025

    A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.

    Source:Byte Reaper
    Published:1 Aug 2025
    7.8
    High

    CVE-2025-41244

    Last Modified: 26 Feb 2026

    VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

    Published:29 Sept 2025
    10
    Critical

    CVE-2025-41243

    Last Modified: 15 Apr 2026

    Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable). * Spring Boot actuator is a dependency. * The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway. * The actuator endpoints are available to attackers. * The actuator endpoints are unsecured.

    Published:16 Sept 2025
    5.9
    Medium

    CVE-2025-41242

    Last Modified: 15 Apr 2026

    Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: * the application is deployed as a WAR or with an embedded Servlet container * the Servlet container does not reject suspicious sequences https://jakarta.ee/specifications/servlet/6.1/jakarta-servlet-spec-6.1.html#uri-path-canonicalization * the application serves static resources https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with Spring resource handling We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as default security features are not disabled in the configuration. Because we cannot check exploits against all Servlet containers and configuration variants, we strongly recommend upgrading your application.

    Published:18 Aug 2025
    4.3
    Medium

    CVE-2025-41228

    Last Modified: 11 Aug 2025

    VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.

    Source:Imraan Khan (Lich-Sec)
    Published:20 May 2025
    10
    Critical

    CVE-2025-41115

    Last Modified: 24 Apr 2026

    SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric externalId, which in turn could allow to override internal user IDs and lead to impersonation or privilege escalation. This vulnerability applies only if all of the following conditions are met: - `enableSCIM` feature flag set to true - `user_sync_enabled` config option in the `[auth.scim]` block set to true

    Published:21 Nov 2025
    7.6
    High

    CVE-2025-41090

    Last Modified: 15 Apr 2026

    microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability. This flaw allows an authenticated user to perform unauthorized actions on other organizations' systems by sending direct API requests. To do so, the attacker can use organization identifiers obtained through a compromised endpoint or deduced manually. This vulnerability allows access between tenants, enabling an attacker to list and manage remote assets, uninstall agents, and even delete vaccines configurations.

    Published:28 Oct 2025
    4.8
    Medium

    CVE-2025-41089

    Last Modified: 15 Apr 2026

    Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.

    Published:10 Oct 2025
    5.1
    Medium

    CVE-2025-41088

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.

    Published:10 Oct 2025
    Items Per Page