Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68955

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2025-68954

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SFTP to remain connected and access files even after their permissions are revoked. A user must have been connected to SFTP at the time of their permissions being revoked in order for this vulnerability

PUBLISHED
Vendor
pterodactyl
Product
panel
Provider severity
HIGH
Conflicts
0

CVE-2025-68953

Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests that are vulnerable to path traversal attacks. Arbitrary files from the server could be retrieved due to a lack of proper sanitization on some requests. This issue is fixed in versions 14.99.6 and 15.88.1. To workaround, changing the setup to use a reverse proxy is recommended.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
HIGH
Conflicts
0

CVE-2025-68952

Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been identified in Eigent. This vulnerability allows an attacker to execute arbitrary code on the victim's machine or server through a specific interaction (1-click). This issue has been patched in version 0.0.61.

PUBLISHED
Vendor
eigent-ai
Product
eigent
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68951

phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vulnerability that allows an attacker to execute arbitrary JavaScript in an administrator’s browser by registering a user whose display name contains HTML entities. When an administrator views the admin user list, the payload is decoded server-side and rendered without escaping, resulting in script execution in the admin context. Version 4.0.16 contains a patch for the issue.

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68950

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows reading the mvg file will be affected. Version 7.1.2-12 fixes the issue.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6895

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

PUBLISHED
Vendor
melapress
Product
Melapress Login Security
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68949

n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely contained the configured whitelist entry as a substring. This issue affected instances where workflow editors relied on IP-based access controls to restrict webhook access. Both IPv4 and IPv6 addresses were impacted. An attacke

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68948

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is stored within the session cookie, an attacker who intercepts or obtains a user's encrypted session cookie (e.g., via session hijacking) can locally decrypt it using the public key. Once decrypted, the

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68947

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

PUBLISHED
Vendor
NSecsoft
Product
NSecKrnl
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68946

In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68945

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68944

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68943

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68942

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68941

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68940

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
LOW
Conflicts
0

CVE-2025-6894

An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged roles. This vulnerability enables the user to perform internal network reconnaissance, potentially discovering internal hosts or services that would otherwise be inaccessible. Repe

PUBLISHED
Vendor
Moxa, Moxa, Moxa, Moxa, Moxa, Moxa, Moxa
Product
EDR-G9010 Series, NAT-102 Series, EDF-G1002-BP Series, OnCell G4302-LTE4 Series, TN-4900 Series, NAT-108 Series, EDR-8010 Series
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68939

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
HIGH
Conflicts
0

CVE-2025-68938

Gitea before 1.25.2 mishandles authorization for deletion of releases.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68937

Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.

PUBLISHED
Vendor
Forgejo
Product
Forgejo
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68936

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

PUBLISHED
Vendor
ONLYOFFICE
Product
Document Server
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68935

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

PUBLISHED
Vendor
ONLYOFFICE
Product
Document Server
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68934

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This affects all users as the shared worker pool becomes exhausted. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. Lowering the max_draft_length site setting reduces attack surface but does not full

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68933

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and restricted categories they cannot access, then export their data to view the content. This is a broken access control vulnerability affecting sites that grant moderators post ownership transfer permissions. This issue is patched in versions 3.5.4, 2025

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68932

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand() and uniqid()) to generate remember-me authentication tokens and challenge-response nonces. This allows attackers to predict valid session tokens, leading to account takeover through persistent session hijacking. The remember-me tokens provide permanent authentication and are the sole credential for "keep me logged in" functionality. This issue has be

PUBLISHED
Vendor
FreshRSS
Product
FreshRSS
Provider severity
LOW
Conflicts
0

CVE-2025-68931

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.

PUBLISHED
Vendor
samrocketman
Product
jervis
Provider severity
HIGH
Conflicts
1

CVE-2025-68930

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypass the Same Origin Policy (SOP) and establish a full-duplex WebSocket connection using a legitimate user's credentials (JSESSIONID). As of time of publication, it is unclear whether a fix is available

PUBLISHED
Vendor
traccar
Product
traccar
Provider severity
HIGH
Conflicts
0

CVE-2025-6893

An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the required permissions, thereby gaining the ability to access or modify system configuration data. Successful exploitation may lead to privilege escalation, allowing the attacker to

PUBLISHED
Vendor
Moxa, Moxa, Moxa, Moxa, Moxa, Moxa, Moxa
Product
NAT-102 Series, EDF-G1002-BP Series, EDR-8010 Series, NAT-108 Series, TN-4900 Series, EDR-G9010 Series, OnCell G4302-LTE4 Series
Provider severity
CRITICAL
Conflicts
1

CVE-2025-68929

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68928

Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.

PUBLISHED
Vendor
frappe
Product
crm
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68927

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSR

PUBLISHED
Vendor
abhinavxd
Product
libredesk
Provider severity
HIGH
Conflicts
0

CVE-2025-68926

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and universally valid across all RustFS deployments. Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute

PUBLISHED
Vendor
rustfs
Product
rustfs
Provider severity
CRITICAL
Conflicts
1

CVE-2025-68925

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.

PUBLISHED
Vendor
samrocketman
Product
jervis
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68924

In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

PUBLISHED
Vendor
Umbraco
Product
Forms
Provider severity
HIGH
Conflicts
0

CVE-2025-68922

OpenOps before 0.6.11 allows remote code execution in the Terraform block.

PUBLISHED
Vendor
OpenOps
Product
OpenOps
Provider severity
HIGH
Conflicts
0

CVE-2025-68921

SteelSeries Nahimic 3 1.10.7 allows Directory traversal.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2025-68920

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

PUBLISHED
Vendor
kermitproject
Product
C-Kermit
Provider severity
HIGH
Conflicts
0

CVE-2025-6892

An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate user has logged in, as the system fails to properly validate session context or privilege boundaries. An attacker may leverage this flaw to perform unauthorized privileged operatio

PUBLISHED
Vendor
Moxa, Moxa, Moxa, Moxa, Moxa, Moxa, Moxa
Product
TN-4900 Series, EDR-8010 Series, EDR-G9010 Series, EDF-G1002-BP Series, NAT-102 Series, NAT-108 Series, OnCell G4302-LTE4 Series
Provider severity
HIGH
Conflicts
1

CVE-2025-68919

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.

PUBLISHED
Vendor
Fujitsu / Fsas Technologies
Product
ETERNUS SF ACM/SC/Express
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68917

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

PUBLISHED
Vendor
ONLYOFFICE
Product
Document Server
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68916

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

PUBLISHED
Vendor
Riello
Product
NetMan
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68915

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

PUBLISHED
Vendor
Riello
Product
NetMan
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68914

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

PUBLISHED
Vendor
Riello
Product
NetMan
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68913

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Miion miion allows PHP Local File Inclusion.This issue affects Miion: from n/a through <= 1.2.7.

PUBLISHED
Vendor
zozothemes
Product
Miion
Provider severity
HIGH
Conflicts
0

CVE-2025-68912

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issue affects HDForms: from n/a through <= 1.6.1.

PUBLISHED
Vendor
Harmonic Design
Product
HDForms
Provider severity
HIGH
Conflicts
0

CVE-2025-68911

Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Solace: from n/a through <= 2.1.16.

PUBLISHED
Vendor
solacewp
Product
Solace
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68910

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee: from n/a through <= 1.0.5.

PUBLISHED
Vendor
blazethemes
Product
Blogzee
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6891

A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Inventory Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-68909

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blogistic: from n/a through <= 1.0.5.

PUBLISHED
Vendor
blazethemes
Product
Blogistic
Provider severity
CRITICAL
Conflicts
0