CVE-2025-7195 2025-12-27 07:08:36 UTC | Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd | MEDIUM 5.2 |
CVE-2025-59946 2025-12-27 00:40:51 UTC | NanoMQ has a Use After Free vulnerability via sub info list | HIGH 7.5 |
CVE-2025-68952 2025-12-27 00:37:09 UTC | 1-click Remote Code Execution (RCE) vulnerability in Eigent | CRITICAL 9.3 |
CVE-2025-68948 2025-12-27 00:21:32 UTC | SiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session Secret | MEDIUM 6.9 |
CVE-2025-68927 2025-12-27 00:04:50 UTC | Improper Neutralization of HTML Tags in a Web Page in libredesk | HIGH 7.3 |
CVE-2025-68474 2025-12-26 23:57:55 UTC | ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling | MEDIUM 6.1 |
CVE-2025-68473 2025-12-26 23:54:48 UTC | ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling | NONE 0.0 |
CVE-2025-68148 2025-12-26 23:46:53 UTC | FreshRSS globally denies access to feed via proxy modifying to 429 Retry-After | MEDIUM 4.3 |
CVE-2025-68932 2025-12-26 23:43:35 UTC | FreshRSS has weak cryptographic randomness in remember-me token and nonce generation | LOW 2.9 |
CVE-2025-66203 2025-12-26 23:37:04 UTC | StreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration Injection | CRITICAL 10.0 |
CVE-2025-68697 2025-12-26 22:12:05 UTC | Self-hosted n8n has Legacy Code node that enables arbitrary file read/write | HIGH 7.1 |
CVE-2025-67729 2025-12-26 22:10:55 UTC | lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() | HIGH 8.8 |
CVE-2025-68668 2025-12-26 21:59:34 UTC | n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node | CRITICAL 9.9 |
CVE-2025-61914 2025-12-26 21:59:25 UTC | n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox | HIGH 7.3 |
CVE-2025-64481 2025-12-26 21:51:26 UTC | Open redirect endpoint in Datasette | LOW 2.7 |
CVE-2018-25153 2025-12-26 21:03:35 UTC | GNU Barcode 0.99 Memory Leak Vulnerability in Command Line Processing | MEDIUM 6.9 |
CVE-2025-68667 2025-12-26 20:49:02 UTC | Conduit-derived homeservers are affected by a Confused Deputy and Improper Input Validation issue | CRITICAL 9.9 |
CVE-2025-14488 2025-12-26 19:37:25 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14497 2025-12-26 19:37:09 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14495 2025-12-26 19:36:35 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14493 2025-12-26 19:36:15 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14496 2025-12-26 19:35:58 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14492 2025-12-26 19:35:40 UTC | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability | HIGH 7.8 |
CVE-2025-14932 2025-12-26 19:34:15 UTC | NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-14933 2025-12-26 19:33:59 UTC | NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-14934 2025-12-26 19:33:30 UTC | NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-15094 2025-12-26 19:32:41 UTC | sunkaifei FlyCMS User Login UserController.java userLogin cross site scripting | MEDIUM 5.3 |
CVE-2025-15095 2025-12-26 19:32:01 UTC | postmanlabs httpbin core.py cross site scripting | MEDIUM 5.1 |
CVE-2025-68941 2025-12-26 19:31:33 UTC | Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. | MEDIUM 4.9 |
CVE-2025-15097 2025-12-26 19:30:52 UTC | Alteryx Server status improper authentication | MEDIUM 6.9 |
CVE-2025-68942 2025-12-26 19:30:04 UTC | Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. | MEDIUM 5.4 |
CVE-2025-15098 2025-12-26 19:29:30 UTC | YunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery | MEDIUM 5.3 |
CVE-2025-68943 2025-12-26 19:28:57 UTC | Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. | MEDIUM 5.3 |
CVE-2025-68944 2025-12-26 19:28:24 UTC | Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. | MEDIUM 5.0 |
CVE-2025-52601 2025-12-26 19:27:45 UTC | Hardcoding sensitive information | MEDIUM 6.3 |
CVE-2025-13158 2025-12-26 19:26:13 UTC | apidoc-core - prototype pollution in api_group.js, api_param_title.js, api_use.js, and api_permission.js worker | CRITICAL 9.3 |
CVE-2025-68946 2025-12-26 18:59:46 UTC | In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. | MEDIUM 5.4 |
CVE-2025-68945 2025-12-26 18:59:30 UTC | In Gitea before 1.21.2, an anonymous user can visit a private user's project. | MEDIUM 5.8 |
CVE-2025-68940 2025-12-26 18:57:57 UTC | In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. | LOW 3.1 |
CVE-2025-68939 2025-12-26 18:57:27 UTC | Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API. | HIGH 8.2 |
CVE-2025-68938 2025-12-26 18:53:35 UTC | Gitea before 1.25.2 mishandles authorization for deletion of releases. | MEDIUM 4.3 |
CVE-2024-44065 2025-12-26 18:35:58 UTC | Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter. | CRITICAL 9.8 |
CVE-2025-24148 2025-12-26 16:48:51 UTC | This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks. | MEDIUM 5.5 |
CVE-2025-43296 2025-12-26 16:44:13 UTC | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks. | MEDIUM 5.5 |
CVE-2025-43348 2025-12-26 16:42:25 UTC | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app may bypass Gatekeeper checks. | MEDIUM 5.5 |
CVE-2025-46291 2025-12-26 16:41:07 UTC | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks. | MEDIUM 5.5 |
CVE-2024-42718 2025-12-26 16:40:08 UTC | A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter. | HIGH 7.5 |
CVE-2025-66737 2025-12-26 16:39:11 UTC | Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component. | MEDIUM 6.5 |
CVE-2025-15082 2025-12-26 16:37:54 UTC | TOZED ZLT M30s Web Management proc_post information disclosure | MEDIUM 6.9 |
CVE-2025-15081 2025-12-26 16:37:10 UTC | JD Cloud BE6500 jdcapi sub_4780 command injection | MEDIUM 5.3 |
CVE-2025-2405 2025-12-26 16:36:33 UTC | XSS in Verisay Communication's Titarus | HIGH 7.6 |
CVE-2025-15073 2025-12-26 16:35:30 UTC | itsourcecode Online Frozen Foods Ordering System contact_us.php sql injection | MEDIUM 6.9 |
CVE-2025-15074 2025-12-26 16:34:54 UTC | itsourcecode Online Frozen Foods Ordering System customer_details.php sql injection | MEDIUM 6.9 |
CVE-2025-15075 2025-12-26 16:34:22 UTC | itsourcecode Student Management System student_p.php sql injection | MEDIUM 6.9 |
CVE-2025-15076 2025-12-26 16:33:52 UTC | Tenda CH22 public path traversal | MEDIUM 6.9 |
CVE-2025-65885 2025-12-26 16:33:12 UTC | An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory. | MEDIUM 5.1 |
CVE-2025-67349 2025-12-26 16:31:58 UTC | A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags. | MEDIUM 6.1 |
CVE-2025-66947 2025-12-26 16:31:09 UTC | SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to infer database contents. Successful exploitation may lead to full database compromise, especially within an administrative module. | MEDIUM 6.5 |
CVE-2025-25341 2025-12-26 16:30:16 UTC | A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS). | HIGH 7.5 |
CVE-2025-67013 2025-12-26 16:29:16 UTC | The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints. | MEDIUM 6.5 |
CVE-2025-67015 2025-12-26 16:28:22 UTC | Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate privileges via sending a crafted POST request to /Forms/admin_access_1. | HIGH 7.5 |
CVE-2025-67014 2025-12-26 16:27:18 UTC | Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access an administrative endpoint. | HIGH 7.5 |
CVE-2024-29720 2025-12-26 16:26:05 UTC | An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video rendering function. | MEDIUM 6.2 |
CVE-2025-57403 2025-12-26 16:24:39 UTC | Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information. | HIGH 7.5 |
CVE-2025-66738 2025-12-26 16:23:22 UTC | An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component. | MEDIUM 6.5 |
CVE-2025-14935 2025-12-26 16:10:30 UTC | NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-14936 2025-12-26 16:09:48 UTC | NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-14925 2025-12-26 16:09:09 UTC | Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-14922 2025-12-26 16:08:36 UTC | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability | HIGH 7.8 |
CVE-2025-8075 2025-12-26 16:01:17 UTC | Improper Input Validation | MEDIUM 5.8 |
CVE-2025-62578 2025-12-26 15:53:18 UTC | DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information | HIGH 7.2 |
CVE-2025-59887 2025-12-26 15:45:29 UTC | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | HIGH 8.6 |
CVE-2025-59888 2025-12-26 15:37:43 UTC | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | MEDIUM 6.7 |
CVE-2025-52598 2025-12-26 15:15:23 UTC | Insufficient certificate validation | MEDIUM 6.3 |
CVE-2025-52599 2025-12-26 15:15:17 UTC | Inadequate account permissions management | MEDIUM 6.3 |
CVE-2025-36192 2025-12-26 15:15:12 UTC | Missing Authorization with the DS8900F and DS8A00 Hardware Management Console | MEDIUM 6.7 |
CVE-2025-36228 2025-12-26 15:15:06 UTC | Incorrect Execution-Assigned Permissions in IBM Aspera Faspex | LOW 3.8 |
CVE-2025-36229 2025-12-26 15:14:58 UTC | Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex | LOW 3.1 |
CVE-2025-36230 2025-12-26 15:14:53 UTC | XSS in IBM Aspera Faspex | MEDIUM 5.4 |
CVE-2025-64645 2025-12-26 15:14:48 UTC | Time-of-check Time-of-use (TOCTOU) in IBM Concert Software. | HIGH 7.7 |
CVE-2025-15091 2025-12-26 15:07:09 UTC | UTT 进取 512W formPictureUrl strcpy buffer overflow | HIGH 8.7 |
CVE-2025-15092 2025-12-26 15:06:19 UTC | UTT 进取 512W ConfigExceptMSN strcpy buffer overflow | HIGH 8.7 |
CVE-2025-15093 2025-12-26 15:05:12 UTC | sunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting | MEDIUM 5.3 |
CVE-2025-15099 2025-12-26 15:04:35 UTC | simstudioai sim CRON Secret internal.ts improper authentication | MEDIUM 6.9 |
CVE-2025-67450 2025-12-26 14:55:52 UTC | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | HIGH 7.8 |
CVE-2025-68922 2025-12-26 14:52:37 UTC | OpenOps before 0.6.11 allows remote code execution in the Terraform block. | HIGH 7.4 |
CVE-2025-32095 2025-12-26 14:52:31 UTC | Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service. | HIGH 7.5 |
CVE-2025-32096 2025-12-26 14:52:26 UTC | Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service. | HIGH 7.5 |
CVE-2025-49088 2025-12-26 14:52:21 UTC | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service. | MEDIUM 5.9 |
CVE-2025-66379 2025-12-26 14:52:15 UTC | Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service. | HIGH 7.5 |
CVE-2025-66443 2025-12-26 14:52:10 UTC | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service. | HIGH 7.5 |
CVE-2025-48704 2025-12-26 14:52:04 UTC | Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service. | HIGH 7.5 |
CVE-2025-59683 2025-12-26 14:51:57 UTC | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service. | HIGH 8.2 |
CVE-2025-66377 2025-12-26 14:51:52 UTC | Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation. | HIGH 7.5 |
CVE-2025-66378 2025-12-26 14:51:46 UTC | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node. | MEDIUM 5.9 |
CVE-2025-2406 2025-12-26 14:51:40 UTC | XSS in Verisay Communication's Trizbi | HIGH 7.6 |
CVE-2025-2307 2025-12-26 14:51:35 UTC | XSS in Verisay Communication's Aidango | HIGH 7.6 |
CVE-2025-68935 2025-12-26 14:51:30 UTC | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer. | MEDIUM 6.4 |
CVE-2025-68936 2025-12-26 14:51:24 UTC | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. | MEDIUM 6.4 |
CVE-2025-14913 2025-12-26 14:51:19 UTC | Frontend Post Submission Manager Lite <= 1.2.6 - Incorrect Authorization to Unauthenticated Arbitrary Attachment Deletion | MEDIUM 5.3 |