4.3
    Medium

    CVE-2025-26202

    Last Modified: 15 Apr 2026

    Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page

    Published:4 Mar 2025
    9.8
    Critical

    CVE-2025-26199

    Last Modified: 9 Jul 2025

    CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.

    Published:18 Jun 2025
    9.8
    Critical

    CVE-2025-26198

    Last Modified: 9 Jul 2025

    CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and bypass authentication, gaining unauthorized administrative access. The vulnerability is triggered when an attacker supplies specially crafted input in the username field, such as ' OR '1'='1, leading to complete compromise of the login mechanism and potential exposure of sensitive backend data.

    Published:18 Jun 2025
    6.1
    Medium

    CVE-2025-26159

    Last Modified: 15 Apr 2026

    Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.

    Published:22 Apr 2025
    5.4
    Medium

    CVE-2025-26153

    Last Modified: 15 Apr 2026

    A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.

    Published:16 Apr 2025
    7.3
    High

    CVE-2025-26125

    Last Modified: 15 Apr 2026

    An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

    Published:17 Mar 2025
    5.4
    Medium

    CVE-2025-26056

    Last Modified: 15 Apr 2026

    A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.

    Published:1 Apr 2025
    6.5
    Medium

    CVE-2025-26055

    Last Modified: 15 Apr 2026

    An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

    Published:1 Apr 2025
    5.4
    Medium

    CVE-2025-26054

    Last Modified: 15 Apr 2026

    Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

    Published:1 Apr 2025
    9.8
    Critical

    CVE-2025-26014

    Last Modified: 13 Jun 2025

    A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.

    Published:21 Feb 2025
    6
    Medium

    CVE-2025-25968

    Last Modified: 30 Sept 2025

    DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml), attackers can bypass access controls, leading to account takeover and potential privilege escalation.

    Published:20 Feb 2025
    6.8
    Medium

    CVE-2025-25967

    Last Modified: 6 Mar 2025

    Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

    Published:3 Mar 2025
    Unknown

    CVE-2025-25965

    https://github.com/Sudo-Sakib/CVE-2025-25965

    Unknown

    CVE-2025-25964

    https://github.com/Sudo-Sakib/CVE-2025-25964

    9.8
    Critical

    CVE-2025-25763

    Last Modified: 7 Jul 2025

    crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php

    Published:6 Mar 2025
    7.1
    High

    CVE-2025-25749

    Last Modified: 7 Apr 2025

    An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.

    Published:11 Mar 2025
    7.3
    High

    CVE-2025-25748

    Last Modified: 29 Jan 2026

    A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.

    Published:11 Mar 2025
    5.4
    Medium

    CVE-2025-25747

    Last Modified: 28 May 2025

    Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

    Published:11 Mar 2025
    Unknown

    CVE-2025-25706

    https://github.com/Cotherm/CVE-2025-25706

    Unknown

    CVE-2025-25705

    https://github.com/Cotherm/CVE-2025-25705

    9.1
    Critical

    CVE-2025-25650

    Last Modified: 15 Apr 2026

    An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.

    Published:17 Mar 2025
    4.3
    Medium

    CVE-2025-25621

    Last Modified: 24 Jun 2025

    Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.

    Published:17 Mar 2025
    5.4
    Medium

    CVE-2025-25620

    Last Modified: 23 Jun 2025

    Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.

    Published:10 Mar 2025
    3.3
    Low

    CVE-2025-25618

    Last Modified: 24 Jun 2025

    Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.

    Published:17 Mar 2025
    4.3
    Medium

    CVE-2025-25617

    Last Modified: 15 Apr 2026

    Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.

    Published:7 Mar 2025
    7.6
    High

    CVE-2025-25616

    Last Modified: 13 Mar 2025

    Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

    Published:10 Mar 2025
    6
    Medium

    CVE-2025-25615

    Last Modified: 13 Mar 2025

    Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.

    Published:10 Mar 2025
    8.8
    High

    CVE-2025-25614

    Last Modified: 23 Jun 2025

    Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

    Published:10 Mar 2025
    7.1
    High

    CVE-2025-25612

    Last Modified: 15 Apr 2026

    FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.

    Published:17 Mar 2025
    Unknown

    CVE-2025-25599

    https://github.com/Certitude-Consulting/CVE-2025-25599

    5.4
    Medium

    CVE-2025-25461

    Last Modified: 9 Jul 2025

    A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can inject a malicious XSS payload into the category name field. When a document is subsequently associated with this category, the payload is stored on the server and rendered without proper sanitization or output encoding. This results in the XSS payload executing in the browser of any user who views the document.

    Published:28 Feb 2025
    4.8
    Medium

    CVE-2025-25460

    Last Modified: 12 Jun 2025

    A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

    Published:24 Feb 2025
    Unknown

    CVE-2025-25369

    https://github.com/lkasjkasj/CVE-2025-25369

    Unknown

    CVE-2025-25347

    https://github.com/Yetazyyy/CVE-2025-25347

    6.1
    Medium

    CVE-2025-25296

    Last Modified: 25 Aug 2025

    Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appropriately crafted `label_config` query parameter. By crafting a specially formatted XML label config with inline task data containing malicious HTML/JavaScript, an attacker can achieve Cross-Site Scripting (XSS). While the application has a Content Security Policy (CSP), it is only set in report-only mode, making it ineffective at preventing script execution. The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Version 1.16.0 contains a patch for the issue.

    Published:14 Feb 2025
    9.9
    Critical

    CVE-2025-25279

    Last Modified: 2 Oct 2025

    Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.

    Published:24 Feb 2025
    9.6
    Critical

    CVE-2025-25257

    Last Modified: 4 Feb 2026

    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

    Source:Milad Karimi (Ex3ptionaL)
    Published:17 Jul 2025
    9.8
    Critical

    CVE-2025-25256

    Last Modified: 18 Aug 2026

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

    Published:12 Aug 2025
    4.8
    Medium

    CVE-2025-25255

    Last Modified: 14 Jan 2026

    An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.

    Published:14 Oct 2025
    6.8
    Medium

    CVE-2025-25254

    Last Modified: 26 Feb 2026

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.

    Published:8 Apr 2025
    6.8
    Medium

    CVE-2025-25253

    Last Modified: 9 Jun 2026

    An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy

    Published:14 Oct 2025
    4.3
    Medium

    CVE-2025-25252

    Last Modified: 14 Jan 2026

    An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.

    Published:14 Oct 2025
    7.5
    High

    CVE-2025-25231

    Last Modified: 15 Apr 2026

    Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

    Published:11 Aug 2025
    7.5
    High

    CVE-2025-25227

    Last Modified: 4 Jun 2025

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

    Published:8 Apr 2025
    9.2
    Critical

    CVE-2025-25200

    Last Modified: 20 Jan 2026

    Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3, Koa uses an evil regex to parse the `X-Forwarded-Proto` and `X-Forwarded-Host` HTTP headers. This can be exploited to carry out a Denial-of-Service attack. Versions 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 fix the issue.

    Published:12 Feb 2025
    7.1
    High

    CVE-2025-25198

    Last Modified: 3 Mar 2026

    mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the `Host HTTP` header to generate a password reset link pointing to an attacker-controlled domain. This can lead to account takeover if a user clicks the poisoned link. Version 2025-01a contains a patch. As a workaround, deactivate the password reset functionality by clearing `Notification email sender` and `Notification email subject` under System -> Configuration -> Options -> Password Settings.

    Source:alvarez
    Published:12 Feb 2025
    7.5
    High

    CVE-2025-25163

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer images-optimizer allows Path Traversal.This issue affects Plugin A/B Image Optimizer: from n/a through <= 3.3.

    Published:7 Feb 2025
    9.6
    Critical

    CVE-2025-25101

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.

    Published:7 Feb 2025
    8.8
    High

    CVE-2025-25064

    Last Modified: 26 Feb 2026

    SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.

    Published:3 Feb 2025
    4.4
    Medium

    CVE-2025-25062

    Last Modified: 23 Jan 2026

    An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.

    Published:3 Feb 2025
    Items Per Page