Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62491

A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->rejected_promise_list). * The function js_std_promise_rejection_check attempts to iterate over the rejected_promise_list to report unhandled rejections using a standard list loop. * The reason for a promise rejection is processed inside the loop, including calling js_std_dump_error1(ctx, rp->reason). * If the promise rejection

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
HIGH
Conflicts
0

CVE-2025-62490

In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a value is not side-effect free. An attacker-defined callback could run during js_print_value, during which the array could get resized and len1 become out of bounds. This results in a use-after-free.A second instance occurs in the same function during printing of a map or set objects. The code iterates over ms->records list, but once again, elements

PUBLISHED
Vendor
QuickJS
Product
QuickJS
Provider severity
HIGH
Conflicts
0

CVE-2025-6249

An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data.

PUBLISHED
Vendor
Lenovo
Product
FileZ Client
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-62487

On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. other dossiers and presentations). On deployments configured with CBAC, the front-end would present a security picker dialog to set the security level on the uploads, thereby mitigating the issue.

PUBLISHED
Vendor
Palantir, Palantir, Palantir
Product
com.palantir.acme:gotham-default-apps-bundle, com.palantir.acme:stencil-app-bundle, com.palantir.acme:dossier-app
Provider severity
LOW
Conflicts
1

CVE-2025-62484

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

PUBLISHED
Vendor
Zoom Communications Inc.
Product
Zoom Workplace
Provider severity
HIGH
Conflicts
0

CVE-2025-62483

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

PUBLISHED
Vendor
Zoom Communications Inc.
Product
Zoom Clients
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62482

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

PUBLISHED
Vendor
Zoom Communications Inc.
Product
Zoom Workplace
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62481

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle Marketing
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62480

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availabi

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
LOW
Conflicts
1

CVE-2025-6248

A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user visits a web page with specially crafted content.

PUBLISHED
Vendor
Lenovo
Product
Browser
Provider severity
HIGH
Conflicts
1

CVE-2025-62479

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 2.7 (Availabilit

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
LOW
Conflicts
1

CVE-2025-62478

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (A

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62477

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62476

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62475

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 4.9 (Availabil

PUBLISHED
Vendor
Oracle Corporation
Product
Oracle ZFS Storage Appliance Kit
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2022, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2025-62473

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2012, Windows Server 2008 R2 Service Pack 1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62472

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2008 Service Pack 2, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows Server 2008 R2 Service Pack 1, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012 R2
Provider severity
HIGH
Conflicts
2

CVE-2025-62470

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2008 R2 Service Pack 1, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2008 Service Pack 2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2025-6247

The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.118.0. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update campaigns and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
ValvePress
Product
WordPress Automatic Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62469

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2025-62468

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 22H3, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62467

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2025-62466

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016, Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2008 R2 Service Pack 1, Windows Server 2019, Windows Server 2008 Service Pack 2, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2008 Service Pack 2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2025-62465

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows 11 version 22H3, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62464

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2025-62463

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62462

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2022, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62461

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2025, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2025-62459

Microsoft Defender Portal Spoofing Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Defender Portal
Provider severity
HIGH
Conflicts
0

CVE-2025-62458

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62457

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2025-62456

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2008 Service Pack 2, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2008 R2 Service Pack 1, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2025-62454

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2025-62453

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62452

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2022, Windows Server 2008 Service Pack 2, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2025-62449

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Visual Studio Code CoPilot Chat Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6244

The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte

PUBLISHED
Vendor
wpdevteam
Product
Essential Addons for Elementor – Popular Elementor Templates & Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62439

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

PUBLISHED
Vendor
Fortinet, Siemens
Product
FortiOS, RUGGEDCOM APE1808
Provider severity
LOW
Conflicts
1

CVE-2025-62430

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo metadata fields. For videos the Tags field and the Genre, Actors, Producer, Executive Producer, and Director fields in Movieinfos accept user supplied values without adequate sanitization. For photos the Photo Title and Photo Tags fields accept user supplied values without adequate sanitization. A regular user who can edit a video or

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62429

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In /upload/admin_area/actions/update_launch.php, the "type" parameter from a POST request is embedded into PHP tags and executed. Proper sanitization is not performed, and by injecting malicious code an attacker can execute arbitrary PHP code. This allows an attacker to achieve RCE. This issue has been resolved in version 5.5.2 #147.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
0

CVE-2025-62428

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an attacker to manipulate the Host header in HTTP requests to generate malicious email confirmation links. These links can redirect users to attacker-controlled domains. This vulnerability affects all users relying on email confirmation for account registration or verification. This vulnerability is fixed

PUBLISHED
Vendor
Drawing-Captcha
Product
Drawing-Captcha-APP
Provider severity
HIGH
Conflicts
0

CVE-2025-62427

The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the URL resolution mechanism of Angular's Server-Side Rendering package (@angular/ssr) before 19.2.18, 20.3.6, and 21.0.0-next.8. The function createRequestUrl uses the native URL constructor. When an incoming request path (e.g., originalUrl or url) begins with a double forward slash (//) or backslash (\\), the URL constructor treats it as a schema-relat

PUBLISHED
Vendor
angular
Product
angular-cli
Provider severity
HIGH
Conflicts
0

CVE-2025-62426

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request parameter that is used in the code before it is properly validated against the chat template. With the right chat_template_kwargs parameters, it is possible to block processing of the API server for long periods of time, delaying all other requests. This issue has been patched in version 0.11.1.

PUBLISHED
Vendor
vllm-project
Product
vllm
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62425

MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without entering the current password. These include changing the current password, adding or removing an e-mail address and deactivating the account. The vulnerability only affects instances whi

PUBLISHED
Vendor
element-hq
Product
matrix-authentication-service
Provider severity
HIGH
Conflicts
0

CVE-2025-62424

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of the file-loading path is inadequate, allowing authenticated administrators to read and write arbitrary files outside the intended template directory by inserting path traversal sequences into the folder parameter. An attacker with administrator privileges can exploit this vulnerability to read sensitive f

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62423

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62422

DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitrary SQL commands. This issue is fixed in version 2.10.14. No known workarounds exist.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
0

CVE-2025-62421

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation and authentication bypass. The StaticResourceApi interface defines a route upload/{fileId} that uses a URL path parameter where both the filename and extension of uploaded files are controllable by users. During permission validation, the TokenFilter invokes the WhitelistUtils#match method to determine if the URL

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
MEDIUM
Conflicts
0