CVE / JVNDB Latest 100

IDDescriptionSeverity
CVE-2025-7195
2025-12-27 07:08:36 UTC

Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

MEDIUM
5.2
CVE-2025-59946
2025-12-27 00:40:51 UTC

NanoMQ has a Use After Free vulnerability via sub info list

HIGH
7.5
CVE-2025-68952
2025-12-27 00:37:09 UTC

1-click Remote Code Execution (RCE) vulnerability in Eigent

CRITICAL
9.3
CVE-2025-68948
2025-12-27 00:21:32 UTC

SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret

MEDIUM
6.9
CVE-2025-68927
2025-12-27 00:04:50 UTC

Improper Neutralization of HTML Tags in a Web Page in libredesk

HIGH
7.3
CVE-2025-68474
2025-12-26 23:57:55 UTC

ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling

MEDIUM
6.1
CVE-2025-68473
2025-12-26 23:54:48 UTC

ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

NONE
0.0
CVE-2025-68148
2025-12-26 23:46:53 UTC

FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After

MEDIUM
4.3
CVE-2025-68932
2025-12-26 23:43:35 UTC

FreshRSS has weak cryptographic randomness in remember-me token and nonce generation

LOW
2.9
CVE-2025-66203
2025-12-26 23:37:04 UTC

StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration Injection

CRITICAL
10.0
CVE-2025-68697
2025-12-26 22:12:05 UTC

Self-hosted n8n has Legacy Code node that enables arbitrary file read/write

HIGH
7.1
CVE-2025-67729
2025-12-26 22:10:55 UTC

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

HIGH
8.8
CVE-2025-68668
2025-12-26 21:59:34 UTC

n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

CRITICAL
9.9
CVE-2025-61914
2025-12-26 21:59:25 UTC

n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

HIGH
7.3
CVE-2025-64481
2025-12-26 21:51:26 UTC

Open redirect endpoint in Datasette

LOW
2.7
CVE-2018-25153
2025-12-26 21:03:35 UTC

GNU Barcode 0.99 Memory Leak Vulnerability in Command Line Processing

MEDIUM
6.9
CVE-2025-68667
2025-12-26 20:49:02 UTC

Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue

CRITICAL
9.9
CVE-2025-14488
2025-12-26 19:37:25 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14497
2025-12-26 19:37:09 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14495
2025-12-26 19:36:35 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14493
2025-12-26 19:36:15 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14496
2025-12-26 19:35:58 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14492
2025-12-26 19:35:40 UTC

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability

HIGH
7.8
CVE-2025-14932
2025-12-26 19:34:15 UTC

NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-14933
2025-12-26 19:33:59 UTC

NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-14934
2025-12-26 19:33:30 UTC

NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-15094
2025-12-26 19:32:41 UTC

sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting

MEDIUM
5.3
CVE-2025-15095
2025-12-26 19:32:01 UTC

postmanlabs httpbin core.py cross site scripting

MEDIUM
5.1
CVE-2025-68941
2025-12-26 19:31:33 UTC

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

MEDIUM
4.9
CVE-2025-15097
2025-12-26 19:30:52 UTC

Alteryx Server status improper authentication

MEDIUM
6.9
CVE-2025-68942
2025-12-26 19:30:04 UTC

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

MEDIUM
5.4
CVE-2025-15098
2025-12-26 19:29:30 UTC

YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery

MEDIUM
5.3
CVE-2025-68943
2025-12-26 19:28:57 UTC

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

MEDIUM
5.3
CVE-2025-68944
2025-12-26 19:28:24 UTC

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

MEDIUM
5.0
CVE-2025-52601
2025-12-26 19:27:45 UTC

Hardcoding sensitive information

MEDIUM
6.3
CVE-2025-13158
2025-12-26 19:26:13 UTC

apidoc-core - prototype pollution in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker

CRITICAL
9.3
CVE-2025-68946
2025-12-26 18:59:46 UTC

In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

MEDIUM
5.4
CVE-2025-68945
2025-12-26 18:59:30 UTC

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

MEDIUM
5.8
CVE-2025-68940
2025-12-26 18:57:57 UTC

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

LOW
3.1
CVE-2025-68939
2025-12-26 18:57:27 UTC

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

HIGH
8.2
CVE-2025-68938
2025-12-26 18:53:35 UTC

Gitea before 1.25.2 mishandles authorization for deletion of releases.

MEDIUM
4.3
CVE-2024-44065
2025-12-26 18:35:58 UTC

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

CRITICAL
9.8
CVE-2025-24148
2025-12-26 16:48:51 UTC

This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.

MEDIUM
5.5
CVE-2025-43296
2025-12-26 16:44:13 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

MEDIUM
5.5
CVE-2025-43348
2025-12-26 16:42:25 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may bypass Gatekeeper checks.

MEDIUM
5.5
CVE-2025-46291
2025-12-26 16:41:07 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

MEDIUM
5.5
CVE-2024-42718
2025-12-26 16:40:08 UTC

A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

HIGH
7.5
CVE-2025-66737
2025-12-26 16:39:11 UTC

Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.

MEDIUM
6.5
CVE-2025-15082
2025-12-26 16:37:54 UTC

TOZED ZLT M30s Web Management proc_post information disclosure

MEDIUM
6.9
CVE-2025-15081
2025-12-26 16:37:10 UTC

JD Cloud BE6500 jdcapi sub_4780 command injection

MEDIUM
5.3
CVE-2025-2405
2025-12-26 16:36:33 UTC

XSS in Verisay Communication's Titarus

HIGH
7.6
CVE-2025-15073
2025-12-26 16:35:30 UTC

itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection

MEDIUM
6.9
CVE-2025-15074
2025-12-26 16:34:54 UTC

itsourcecode Online Frozen Foods Ordering System customer_details.php sql injection

MEDIUM
6.9
CVE-2025-15075
2025-12-26 16:34:22 UTC

itsourcecode Student Management System student_p.php sql injection

MEDIUM
6.9
CVE-2025-15076
2025-12-26 16:33:52 UTC

Tenda CH22 public path traversal

MEDIUM
6.9
CVE-2025-65885
2025-12-26 16:33:12 UTC

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory.

MEDIUM
5.1
CVE-2025-67349
2025-12-26 16:31:58 UTC

A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.

MEDIUM
6.1
CVE-2025-66947
2025-12-26 16:31:09 UTC

SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module.

MEDIUM
6.5
CVE-2025-25341
2025-12-26 16:30:16 UTC

A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).

HIGH
7.5
CVE-2025-67013
2025-12-26 16:29:16 UTC

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

MEDIUM
6.5
CVE-2025-67015
2025-12-26 16:28:22 UTC

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1.

HIGH
7.5
CVE-2025-67014
2025-12-26 16:27:18 UTC

Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint.

HIGH
7.5
CVE-2024-29720
2025-12-26 16:26:05 UTC

An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function.

MEDIUM
6.2
CVE-2025-57403
2025-12-26 16:24:39 UTC

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.

HIGH
7.5
CVE-2025-66738
2025-12-26 16:23:22 UTC

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

MEDIUM
6.5
CVE-2025-14935
2025-12-26 16:10:30 UTC

NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-14936
2025-12-26 16:09:48 UTC

NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-14925
2025-12-26 16:09:09 UTC

Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-14922
2025-12-26 16:08:36 UTC

Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability

HIGH
7.8
CVE-2025-8075
2025-12-26 16:01:17 UTC

Improper Input Validation

MEDIUM
5.8
CVE-2025-62578
2025-12-26 15:53:18 UTC

DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

HIGH
7.2
CVE-2025-59887
2025-12-26 15:45:29 UTC

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

HIGH
8.6
CVE-2025-59888
2025-12-26 15:37:43 UTC

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

MEDIUM
6.7
CVE-2025-52598
2025-12-26 15:15:23 UTC

Insufficient certificate validation

MEDIUM
6.3
CVE-2025-52599
2025-12-26 15:15:17 UTC

Inadequate account permissions management

MEDIUM
6.3
CVE-2025-36192
2025-12-26 15:15:12 UTC

Missing Authorization with the DS8900F and DS8A00 Hardware Management Console

MEDIUM
6.7
CVE-2025-36228
2025-12-26 15:15:06 UTC

Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

LOW
3.8
CVE-2025-36229
2025-12-26 15:14:58 UTC

Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex

LOW
3.1
CVE-2025-36230
2025-12-26 15:14:53 UTC

XSS in IBM Aspera Faspex

MEDIUM
5.4
CVE-2025-64645
2025-12-26 15:14:48 UTC

Time-of-check Time-of-use (TOCTOU) in IBM Concert Software.

HIGH
7.7
CVE-2025-15091
2025-12-26 15:07:09 UTC

UTT 进取 512W formPictureUrl strcpy buffer overflow

HIGH
8.7
CVE-2025-15092
2025-12-26 15:06:19 UTC

UTT 进取 512W ConfigExceptMSN strcpy buffer overflow

HIGH
8.7
CVE-2025-15093
2025-12-26 15:05:12 UTC

sunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting

MEDIUM
5.3
CVE-2025-15099
2025-12-26 15:04:35 UTC

simstudioai sim CRON Secret internal.ts improper authentication

MEDIUM
6.9
CVE-2025-67450
2025-12-26 14:55:52 UTC

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center.

HIGH
7.8
CVE-2025-68922
2025-12-26 14:52:37 UTC

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

HIGH
7.4
CVE-2025-32095
2025-12-26 14:52:31 UTC

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.

HIGH
7.5
CVE-2025-32096
2025-12-26 14:52:26 UTC

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

HIGH
7.5
CVE-2025-49088
2025-12-26 14:52:21 UTC

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.

MEDIUM
5.9
CVE-2025-66379
2025-12-26 14:52:15 UTC

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

HIGH
7.5
CVE-2025-66443
2025-12-26 14:52:10 UTC

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.

HIGH
7.5
CVE-2025-48704
2025-12-26 14:52:04 UTC

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

HIGH
7.5
CVE-2025-59683
2025-12-26 14:51:57 UTC

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

HIGH
8.2
CVE-2025-66377
2025-12-26 14:51:52 UTC

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.

HIGH
7.5
CVE-2025-66378
2025-12-26 14:51:46 UTC

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

MEDIUM
5.9
CVE-2025-2406
2025-12-26 14:51:40 UTC

XSS in Verisay Communication's Trizbi

HIGH
7.6
CVE-2025-2307
2025-12-26 14:51:35 UTC

XSS in Verisay Communication's Aidango

HIGH
7.6
CVE-2025-68935
2025-12-26 14:51:30 UTC

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

MEDIUM
6.4
CVE-2025-68936
2025-12-26 14:51:24 UTC

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

MEDIUM
6.4
CVE-2025-14913
2025-12-26 14:51:19 UTC

Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion

MEDIUM
5.3