Latest CVE Feed
-
7.5
HIGHCVE-2025-61557
nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Path Traversal
-
7.0
HIGHCVE-2025-61037
A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges... Read more
Affected Products :- Published: Dec. 31, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-50343
An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees d... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-68914
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.... Read more
Affected Products : netman_208- Published: Dec. 24, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-68915
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.... Read more
Affected Products : netman_208- Published: Dec. 24, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-67108
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.... Read more
Affected Products : fast_dds- Published: Dec. 23, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cryptography
-
9.9
CRITICALCVE-2025-67164
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : pagekit- Published: Dec. 17, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-67165
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.... Read more
Affected Products : pagekit- Published: Dec. 17, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-67285
A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL quer... Read more
Affected Products : covid_tracking_system_using_qr-code- Published: Dec. 17, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
9.6
CRITICALCVE-2025-67289
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.... Read more
- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-67290
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.... Read more
Affected Products : piranha_cms- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-67291
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.... Read more
Affected Products : piranha_cms- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-67418
ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default cred... Read more
Affected Products : clipbucket- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-67436
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).... Read more
Affected Products : pluxml- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Injection
-
7.6
HIGHCVE-2025-67442
EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.... Read more
Affected Products : eve-ng- Published: Dec. 19, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-67443
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.... Read more
Affected Products : cms- Published: Dec. 22, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-68115
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email ve... Read more
Affected Products : parse-server- Published: Dec. 16, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
8.9
HIGHCVE-2025-68116
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An at... Read more
Affected Products : filerise- Published: Dec. 16, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-66023
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Free (UAF) vulnerability within the MQTT bridge client component (implemented via the underlying NanoNNG library). The vulnerability is tr... Read more
Affected Products :- Published: Jan. 01, 2026
- Modified: Jan. 02, 2026
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-15398
A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The at... Read more
Affected Products :- Published: Dec. 31, 2025
- Modified: Jan. 02, 2026
- Vuln Type: Authentication