Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62721

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, regardless of their ownership or visibility settings. This issue is fixed in version 2.4.0.

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
HIGH
Conflicts
1

CVE-2025-62720

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system, including private links that should only be accessible to their owners. The HTML and CSV export functions in the ExportController class retrieve all links without applying any ownership or visibility filtering, effectively bypassing all access controls implemented elsewhere in the application. This issue is fixed in

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
HIGH
Conflicts
1

CVE-2025-6272

A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
wasm3
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62719

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination is not an internal or private network resource. This Server-Side Request Forgery (SSRF) vulnerability allows authenticated attackers to use the application server to perform port scanning and service discovery on internal networks. Practical impact is

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
LOW
Conflicts
0

CVE-2025-62718

A flaw was found in Axios, a promise-based HTTP client. This vulnerability occurs because Axios does not correctly handle hostname normalization when evaluating NO_PROXY rules. An attacker can exploit this by crafting requests to loopback addresses (e.g., localhost. or [::1]) which bypass the NO_PROXY configuration and are routed through the configured proxy. This can lead to Server-Side Request Forgery (SSRF) vulnerabilities, enabling attackers to access sensitive internal or loopback services

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Virtualization 4, Red Hat Build of Kueue, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 2.6, Red Hat Developer Hub, OpenShift Service Mesh 3, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI 2.25, OpenShift Service Mesh 3, Cluster Observability Operator 1.5.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Discovery 2, Gatekeeper 3, Red Hat Build of Kueue, Self-service automation portal 2, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift Container Platform 4, Network Observability (NETOBSERV) 1.11.1, OpenShift Service Mesh 3, Red Hat Quay 3.1, Red Hat Quay 3.9, Red Hat 3scale API Management Platform 2, Red Hat Developer Hub 1.8, Red Hat OpenShift Service Mesh 2.6, Red Hat Ansible Automation Platform 2.6, Red Hat Quay 3.16, Red Hat 3scale API Management Platform 2, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Quay 3, Red Hat Data Grid 8, axios, Red Hat OpenShift Service Mesh 3.0, Red Hat Quay 3.15, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Red Hat 3scale API Management Platform 2, Red Hat Quay 3.14, OpenShift Service Mesh 2, Red Hat OpenShift AI 2.25, Red Hat Quay 3, Red Hat Ansible Automation Platform 2, Red Hat Quay 3, Red Hat Quay 3, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Service Mesh 3.1, OpenShift Service Mesh 3, Red Hat Migration Toolkit 1.8, Red Hat Quay 3.17, OpenShift Service Mesh 3, Red Hat build of Apicurio Registry 3, Red Hat OpenShift Service Mesh 3.2, Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 3, Red Hat Trusted Profile Analyzer, Red Hat Developer Hub 1.9, Red Hat Ansible Automation Platform 2, multicluster engine for Kubernetes 2.8, Red Hat build of Apache Camel - HawtIO 4, Multicluster Engine for Kubernetes, Red Hat Fuse 7, OpenShift Service Mesh 3, Cluster Observability Operator 1.5.0, Red Hat Trusted Profile Analyzer, Red Hat Ansible Automation Platform 2.5, Cluster Observability Operator 1.5.0, Red Hat OpenShift Virtualization 4, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 3, Migration Toolkit for Applications 8, OpenShift Service Mesh 3, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat Build of Kueue, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 2, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2.14, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.0, Red Hat Quay 3, Migration Toolkit for Applications 8, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift Service Mesh 3.2, Red Hat Process Automation 7, Red Hat OpenShift Virtualization 4, Red Hat 3scale API Management Platform 2, Migration Toolkit for Applications 8, Red Hat Advanced Cluster Security 4.9, Red Hat Satellite 6, Multicluster Engine for Kubernetes, Red Hat Quay 3, Red Hat Quay 3.12, Network Observability Operator, Red Hat Trusted Artifact Signer 1.3, OpenShift Pipelines, Gatekeeper 3, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI 3.3, Cluster Observability Operator 1.5.0, Network Observability (NETOBSERV) 1.11.1, Red Hat Ansible Automation Platform 2, Red Hat Build of Kueue, streams for Apache Kafka 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Streams for Apache Kafka 3.2.0, OpenShift Pipelines, Red Hat OpenShift AI 3.3, OpenShift Service Mesh 3, Cryostat 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift Container Platform 4, Red Hat Quay 3, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2025-62717

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing logic error. This means the verification code could be reused anywhere an email verification code is required. This issue has been fixed in commit 1f726df.

PUBLISHED
Vendor
emlog
Product
emlog
Provider severity
LOW
Conflicts
0

CVE-2025-62716

Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to supply arbitrary schemes (e.g., javascript:) that are passed directly to router.push. This results in a cross-site scripting (XSS) vulnerability, enabling attackers to execute arbitrary JavaScript in the victim’s browser. The issue can be exploited without authentication and has severe impact, including information disclosure, and privileg

PUBLISHED
Vendor
makeplane
Product
plane
Provider severity
HIGH
Conflicts
1

CVE-2025-62715

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. An authenticated normal user can create a tag containing HTML or JavaScript, which is later rendered unescaped in collection detail and tag-list pages. As a result, arbitrary JavaScript executes in the browsers of all users who view the affected pages. This issue is fixed in version 5.5.2-#152.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62714

Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce authentication, allowing unauthenticated users to access sensitive cluster information such as Secrets and Services directly. Although the web UI required a valid JWT for access, the API itself r

PUBLISHED
Vendor
karmada-io
Product
dashboard
Provider severity
HIGH
Conflicts
0

CVE-2025-62713

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected. This issue has been fixed in version 3.3.2.

PUBLISHED
Vendor
kottster
Product
kottster
Provider severity
HIGH
Conflicts
1

CVE-2025-62712

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection API endpoint (/api/v1/authentication/super-connection-token/). When accessed from a web browser, this endpoint returns connection tokens created by all users instead of restricting results to tokens owned by or authorize

PUBLISHED
Vendor
jumpserver
Product
jumpserver
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62711

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.

PUBLISHED
Vendor
bytecodealliance
Product
wasmtime
Provider severity
LOW
Conflicts
0

CVE-2025-62710

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest

PUBLISHED
Vendor
sakaiproject
Product
sakai
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6271

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
swftools
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62709

ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from the incoming HTTP Host header when the configuration base_url is not set. Because Host is a client-controlled header, an attacker can supply an arbitrary Host value. This allows an attacker to cause password-reset links (sent by forget.php) to be generated with the attacker’s domain. If a victim follows that link and en

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62708

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf version 6.1.3.

PUBLISHED
Vendor
py-pdf
Product
pypdf
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62707

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.

PUBLISHED
Vendor
py-pdf
Product
pypdf
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62706

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can expand into tens or hundreds of megabytes on decrypt, allowing an attacker who can supply decryptable tokens to exhaust memory and CPU and cause denial of service. This issue has been patched in version 1.6.5. Workarounds for this issue involve rejecting or stripping zip=DEF for inbound JWEs at the appl

PUBLISHED
Vendor
authlib
Product
authlib
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62705

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than strings. This includes, but is not limited to sys/raw with use of encoding=base64, all data would be emitted unredacted to the audit log, and Transit, when performing a signing operation with a derived Ed25519 key, would emit public keys to the audit log. This issue has been patched

PUBLISHED
Vendor
openbao
Product
openbao
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62703

Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle deserialization via FlaskRPCServer. The Fugue framework implements an RPC server system for distributed computing operations. In the core functionality of the RPC server implementation, I found that the _decode() function in fugue/rpc/flask.py directly uses cl

PUBLISHED
Vendor
fugue-project
Product
fugue
Provider severity
HIGH
Conflicts
0

CVE-2025-62702

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - PageTriage Extension allows Stored XSS.This issue affects Mediawiki - PageTriage Extension: from master before 1.44.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - PageTriage Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62701

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikistories allows Stored XSS.This issue affects Mediawiki - Wikistories: from master before 1.44.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - Wikistories
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62700

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - MultiBoilerplate Extensionmaste allows Stored XSS.This issue affects Mediawiki - MultiBoilerplate Extensionmaste: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - MultiBoilerplate Extensionmaste
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6270

A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the file H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
HDF5
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62699

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Translate Extension allows Footprinting. Translate extension appears to use jobs to make edits to translation pages. This causes the CheckUser tool to log the wrong IP and User-Agent making these edits un-auditable via the CheckUser tool.This issue affects Mediawiki - Translate Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - Translate Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62698

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - ExternalGuidance allows Stored XSS.This issue affects Mediawiki - ExternalGuidance: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - ExternalGuidance
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62697

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - LanguageSelector Extension
Provider severity
HIGH
Conflicts
0

CVE-2025-62696

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki Foundation - Springboard Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62695

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Stored XSS.This issue affects Mediawiki - WikiLambda Extension: master.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - WikiLambda Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62694

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - WikiLove Extension allows Stored XSS.This issue affects Mediawiki - WikiLove Extension: 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - WikiLove Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62693

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - LastModified Extension allows Stored XSS.This issue affects Mediawiki - LastModified Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - LastModified Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62691

Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HTTP headers. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.

PUBLISHED
Vendor
Intercom, Inc., Intercom, Inc.
Product
Security Point (Windows) of MaLion, Security Point (Windows) of MaLionCloud
Provider severity
CRITICAL
Conflicts
2

CVE-2025-62690

Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
LOW
Conflicts
0

CVE-2025-6269

A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
HDF5
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62689

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

PUBLISHED
Vendor
GNU Project
Product
GNU libbmicrohttpd
Provider severity
HIGH
Conflicts
1

CVE-2025-62688

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials to change their role, gaining full control access to the project.

PUBLISHED
Vendor
AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect
Product
Productivity 1000 P1-540 CPU, Productivity 3000 P3-622 CPU, Productivity 1000 P1-550 CPU, Productivity 2000 P2-550 CPU, Productivity Suite, Productivity 3000 P3-550E CPU, Productivity 3000 P3-530 CPU, Productivity 2000 P2-622 CPU
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62687

Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed.

PUBLISHED
Vendor
LogStare Inc., LogStare Inc.
Product
LogStare Collector (for Linux), LogStare Collector (for Windows)
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62686

A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a local user may exploit the DYLD_INSERT_LIBRARIES environment variable to inject a dynamic library, potentially resulting in code execution with elevated privileges.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2025-6268

A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function of the file /luna/servlet/view/search. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Luna
Product
Imaging
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62676

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages.

PUBLISHED
Vendor
Fortinet
Product
FortiClientWindows
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62675

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.

PUBLISHED
Vendor
Fortinet, Fortinet, Fortinet
Product
FortiProxy, FortiPAM, FortiOS
Provider severity
LOW
Conflicts
1

CVE-2025-62674

The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

PUBLISHED
Vendor
iCam365, iCam365
Product
QC021, P201
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62673

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Archer AX53 v1.0
Provider severity
HIGH
Conflicts
0

CVE-2025-62672

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication.

PUBLISHED
Vendor
boyns
Product
rplay
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62671

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: master.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62670

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - FlexDiagrams Extension allows Stored XSS.This issue affects Mediawiki - FlexDiagrams Extension: master.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - FlexDiagrams Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6267

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /adpweb/a/base/barcodeDetail/. The manipulation of the argument barcodeNo/barcode/itemNo leads to sql injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
zhilink 智互联(深圳)科技有限公司
Product
ADP Application Developer Platform 应用开发者平台
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62669

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - CentralAuth Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62668

Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Resource Leak Exposure.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - GrowthExperiments Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62667

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Stored XSS.This issue affects Mediawiki - GrowthExperiments Extension: from master before 1.39.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - GrowthExperiments Extension
Provider severity
MEDIUM
Conflicts
0