Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-68622

Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in the esp-usb UVC host implementation allows a malicious USB Video Class (UVC) device to trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor printing is enabled, the host prints detailed descriptor information provided by the connected USB device. A specially crafted UVC descriptor may advertise an excessively large length. B

PUBLISHED
Vendor
espressif
Product
esp-usb
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68621

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base.

PUBLISHED
Vendor
TriliumNext
Product
Trilium
Provider severity
HIGH
Conflicts
0

CVE-2025-68620

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated polling of access request status. The first is Unauthenticated WebSocket Request Enumeration: When a WebSocket client connects to the SignalK stream endpoint with the `serverevents=all` query parameter,

PUBLISHED
Vendor
SignalK
Product
signalk-server
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6862

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68619

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin or webapp, the version parameter accepts arbitrary npm version specifiers including URLs. npm supports installing packages from git repositories, GitHub shorthand syntax, and HTTP/HTTPS URLs pointing t

PUBLISHED
Vendor
SignalK
Product
signalk-server
Provider severity
HIGH
Conflicts
0

CVE-2025-68618

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68617

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading to use of freed memory, if the synthesizer is being concurrently destroyed, or samples of the (unloaded) DLS file are concurrently used to synthesize audio. This issue has been patched in version 2.5.2. The problem will n

PUBLISHED
Vendor
FluidSynth
Product
fluidsynth
Provider severity
HIGH
Conflicts
0

CVE-2025-68616

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadata endpoints) even when a developer has implemented a custom `url_fetcher` to block such access. This occurs because the underlying `urllib` library follows HTTP redirects automatically without re-valid

PUBLISHED
Vendor
Red Hat, Kozea
Product
Red Hat Ansible Automation Platform 2, WeasyPrint
Provider severity
HIGH
Conflicts
2

CVE-2025-68615

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

PUBLISHED
Vendor
net-snmp
Product
net-snmp
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68614

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.

PUBLISHED
Vendor
librenms
Product
librenms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68613

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execut

PUBLISHEDCISA KEV
Vendor
n8n-io
Product
n8n
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6861

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/price leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68609

A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.

PUBLISHED
Vendor
Palantir
Product
com.palantir.aries:aries
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68608

Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Userpro: from n/a through <= 5.1.9.

PUBLISHED
Vendor
DeluxeThemes
Product
Userpro
Provider severity
HIGH
Conflicts
0

CVE-2025-68607

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a through <= 2.7.7.

PUBLISHED
Vendor
Hiroaki Miyashita
Product
Custom Field Template
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68606

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.

PUBLISHED
Vendor
WPXPO
Product
PostX
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68605

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.

PUBLISHED
Vendor
PickPlugins
Product
Post Grid and Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68604

Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3.

PUBLISHED
Vendor
WPGraphQL
Product
WPGraphQL
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68603

Missing Authorization vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editorial Calendar: from n/a through <= 3.8.8.

PUBLISHED
Vendor
Marketing Fire
Product
Editorial Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68602

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2.

PUBLISHED
Vendor
Scott Paterson
Product
Accept Donations with PayPal & Stripe
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68601

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8.

PUBLISHED
Vendor
Rustaurius
Product
Five Star Restaurant Reservations
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68600

Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7.

PUBLISHED
Vendor
Yannick Lefebvre
Product
Link Library
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6860

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68599

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube Plugin Support YouTube Embed youtube-embed allows Stored XSS.This issue affects YouTube Embed: from n/a through <= 5.4.

PUBLISHED
Vendor
Embeds For YouTube Plugin Support
Product
YouTube Embed
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68598

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.

PUBLISHED
Vendor
LiveComposer
Product
Page Builder: Live Composer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68597

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2.8.1.

PUBLISHED
Vendor
BlueGlass Interactive AG
Product
Jobs for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68596

Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11.

PUBLISHED
Vendor
Bit Apps
Product
Bit Assist
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68595

Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widgets for Social Photo Feed: from n/a through <= 1.8.

PUBLISHED
Vendor
Trustindex
Product
Widgets for Social Photo Feed
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68594

Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0.

PUBLISHED
Vendor
Opinion Stage
Product
Poll, Survey & Quiz Maker Plugin by Opinion Stage
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68593

Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.

PUBLISHED
Vendor
Liton Arefin
Product
WP Adminify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68592

Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.

PUBLISHED
Vendor
Liton Arefin
Product
WP Adminify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68591

Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.18.

PUBLISHED
Vendor
Mitchell Bennis
Product
Simple File List
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68590

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2.

PUBLISHED
Vendor
CRM Perks
Product
Integration for Contact Form 7 HubSpot
Provider severity
HIGH
Conflicts
0

CVE-2025-6859

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/pro_sale.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68589

Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.12.

PUBLISHED
Vendor
WP Socio
Product
WP Telegram Widget and Join Link
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68588

Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Poll: from n/a through <= 2.5.5.

PUBLISHED
Vendor
totalsoft
Product
TS Poll
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68587

Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watu Quiz: from n/a through <= 3.4.5.

PUBLISHED
Vendor
Bob
Product
Watu Quiz
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68586

Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.3.

PUBLISHED
Vendor
Gora Tech
Product
Cooked
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68585

Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2.

PUBLISHED
Vendor
Ben Balter
Product
WP Document Revisions
Provider severity
LOW
Conflicts
0

CVE-2025-68584

Cross-Site Request Forgery (CSRF) vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-post-lite allows Cross Site Request Forgery.This issue affects Vimeotheque: from n/a through <= 2.3.5.2.

PUBLISHED
Vendor
Constantin Boiangiu
Product
Vimeotheque
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68583

Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10.

PUBLISHED
Vendor
Tikweb Management
Product
Fast User Switching
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68582

Missing Authorization vulnerability in Funnelforms Funnelforms Free funnelforms-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Funnelforms Free: from n/a through <= 3.8.

PUBLISHED
Vendor
Funnelforms
Product
Funnelforms Free
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68581

Missing Authorization vulnerability in YITHEMES YITH Slider for page builders yith-slider-for-page-builders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH Slider for page builders: from n/a through <= 1.0.11.

PUBLISHED
Vendor
YITHEMES
Product
YITH Slider for page builders
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68580

Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9.

PUBLISHED
Vendor
pluginsware
Product
Advanced Classifieds & Directory Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6858

A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
HDF5
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-68579

Missing Authorization vulnerability in FolioVision FV Simpler SEO fv-all-in-one-seo-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FV Simpler SEO: from n/a through <= 1.9.6.

PUBLISHED
Vendor
FolioVision
Product
FV Simpler SEO
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68578

Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify: from n/a through <= 2.0.4.

PUBLISHED
Vendor
Addonify
Product
Addonify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68577

Missing Authorization vulnerability in Virusdie Virusdie virusdie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Virusdie: from n/a through <= 1.1.6.

PUBLISHED
Vendor
Virusdie
Product
Virusdie
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68576

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Virusdie Virusdie virusdie allows Retrieve Embedded Sensitive Data.This issue affects Virusdie: from n/a through <= 1.1.6.

PUBLISHED
Vendor
Virusdie
Product
Virusdie
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68575

Missing Authorization vulnerability in Wappointment team Wappointment wappointment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wappointment: from n/a through <= 2.7.6.

PUBLISHED
Vendor
Wappointment team
Product
Wappointment
Provider severity
MEDIUM
Conflicts
0