Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62607

Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view the Service Now public instance name e.g. companyname.service-now.com. This is considered low-value information. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain acces

PUBLISHED
Vendor
nautobot
Product
nautobot-app-ssot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62606

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 2.5.12.

PUBLISHED
Vendor
My-Little-Forum
Product
mylittleforum
Provider severity
HIGH
Conflicts
0

CVE-2025-62605

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, but it is possible for an attacker to bypass these controls in Mastodon versions prior to 4.4.8 and 4.5.0-beta.2. Mastodon internally treats reblogs as statuses. Since they were not special-treated, an attacker could reblog any post, then quote their reblog, technically quoting themselves, but having the quote feature a preview of

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62604

MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information. This allows an unauthenticated attacker to log in to the system as any user. This issue has been patched in version 2.10.25-lts.

PUBLISHED
Vendor
metersphere
Product
metersphere
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62603

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-message container that carries not only the handshake but also on going security-control traffic after the handshake, such as crypto-token exchange, rekeying, re-authentication, and token delivery for newly appearing endpoints. On receive, the CDR parser is invoked first and deserializes the `message_data` (i .e., the `Data

PUBLISHED
Vendor
eProsima
Product
Fast-DDS
Provider severity
LOW
Conflicts
0

CVE-2025-62602

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overflow, resulting in remote termination of Fast-DDS. If the fields of `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage are tampered with — specially `readOctetVector` reads an unch

PUBLISHED
Vendor
eProsima
Product
Fast-DDS
Provider severity
LOW
Conflicts
0

CVE-2025-62601

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overflow, resulting in remote termination of Fast-DDS. If the fields of `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage — specifically by tampering with the `str_size` value read by

PUBLISHED
Vendor
eProsima
Product
Fast-DDS
Provider severity
LOW
Conflicts
0

CVE-2025-62600

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If the fields of PID_IDENTITY_TOKEN or PID_PERMISSION_TOKEN in the DATA Submessage — specifically by tampering with the length fi

PUBLISHED
Vendor
eProsima
Product
Fast-DDS
Provider severity
HIGH
Conflicts
1

CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.

PUBLISHED
Vendor
Network Thermostat
Product
X-Series WiFi thermostats
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62599

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If the fields of PID_IDENTITY_TOKEN or PID_PERMISSION_TOKEN in the DATA Submessage — specifically by tampering with the length fi

PUBLISHED
Vendor
eProsima
Product
Fast-DDS
Provider severity
HIGH
Conflicts
1

CVE-2025-62598

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the action parameter. The vulnerable endpoint is GET /WeGIA/html/pessoa/editar_info_pessoal.php?action=1. This issue has been patched in version 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62597

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the sql parameter. The vulnerable endpoint is GET /WeGIA/html/pessoa/editar_info_pessoal.php?sql=1. This issue has been patched in version 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62596

Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficiently strict write-target validation, and when combined with path substitution during pathname resolution, can allow writes to unintended procfs locations. While resolving a path component-by-component, a shared-mount race can substitute intermediate components and redirect the final target. This issue is fixed in version 0.5.7.

PUBLISHED
Vendor
youki-dev
Product
youki
Provider severity
HIGH
Conflicts
1

CVE-2025-62595

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the Referer header to force a user’s browser to navigate to an external, potentially malicious website. This occurs because the implementation incorrectly treats some specially crafted URLs as safe relativ

PUBLISHED
Vendor
koajs
Product
koa
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62594

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62593

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DN

PUBLISHED
Vendor
ray-project
Product
ray
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62592

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62591

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62590

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
HIGH
Conflicts
1

CVE-2025-6259

The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
geoplay9
Product
esri-map-view
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62589

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
HIGH
Conflicts
1

CVE-2025-62588

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
HIGH
Conflicts
1

CVE-2025-62587

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle VM VirtualBox
Provider severity
HIGH
Conflicts
1

CVE-2025-62586

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

PUBLISHED
Vendor
OPEXUS
Product
FOIAXpress
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2025-62585

Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

PUBLISHED
Vendor
NAVER
Product
NAVER Whale browser
Provider severity
HIGH
Conflicts
0

CVE-2025-62584

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

PUBLISHED
Vendor
NAVER
Product
NAVER Whale browser
Provider severity
HIGH
Conflicts
0

CVE-2025-62583

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

PUBLISHED
Vendor
NAVER
Product
NAVER Whale browser
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62582

Delta Electronics DIAView has multiple vulnerabilities.

PUBLISHED
Vendor
Delta Electronics
Product
DIAView
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2025-62581

Delta Electronics DIAView has multiple vulnerabilities.

PUBLISHED
Vendor
Delta Electronics
Product
DIAView
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62580

ASDA-Soft Stack-based Buffer Overflow Vulnerability

PUBLISHED
Vendor
Delta Electronics
Product
ASDA-Soft
Provider severity
HIGH
Conflicts
0

CVE-2025-6258

The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track shortcode in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
grosbouff
Product
WP SoundSystem
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62579

ASDA-Soft Stack-based Buffer Overflow Vulnerability

PUBLISHED
Vendor
Delta Electronics
Product
ASDA-Soft
Provider severity
HIGH
Conflicts
0

CVE-2025-62578

DVP-12SE - Modbus/TCP Cleartext Transmission of Sensitive Information

PUBLISHED
Vendor
Delta Electronics
Product
DVP-12SE
Provider severity
HIGH
Conflicts
0

CVE-2025-62577

ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.

PUBLISHED
Vendor
Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc., Fsas Technologies Inc.
Product
ETERNUS SF Expressn (for RHEL 7/ 8/ 9), ETERNUS SF Express (for Windows Server 2016/ 2019/ 2022), ETERNUS SF AdvancedCopy Manager Standard Edition (for Solaris 10/ 11), ETERNUS SF Storage Cruiser (for Windows Server 2016/ 2019/ 2022), ETERNUS SF Storage Cruisern (for RHEL 7/ 8/ 9), ETERNUS SF Storage Cruiser (for Solaris 10/ 11), ETERNUS SF AdvancedCopy Manager Standard Edition (for Windows Server 2016/ 2019/ 2022), ETERNUS SF AdvancedCopy Manager Standard Edition (for RHEL 7/ 8/ 9)
Provider severity
HIGH
Conflicts
2

CVE-2025-62575

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.

PUBLISHED
Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
Provider severity
HIGH
Conflicts
1

CVE-2025-62573

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2025, Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2025-62572

Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62571

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2016, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 R2 Service Pack 1
Provider severity
HIGH
Conflicts
1

CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2025-6257

The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currency shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
joostdekeijzer
Product
Euro FxRef Currency Converter (by DKZR)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62569

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2025-62567

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 11 version 22H3, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2025, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62565

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019, Windows 10 Version 1809, Windows 11 version 22H3, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62564

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Office Online Server, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2025-62563

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2025-62562

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft Word 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft SharePoint Server 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2025-62561

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Excel 2016
Provider severity
HIGH
Conflicts
1

CVE-2025-62560

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019
Provider severity
HIGH
Conflicts
2

CVE-2025-6256

The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
dragwp
Product
Flex Guten – Multile Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62559

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Enterprise Server 2016, Microsoft Office 2019, Microsoft Word 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1