Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62374

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode (internal) are affected. This vulnerability is fixed in 7.0.0.

PUBLISHED
Vendor
parse-community
Product
Parse-SDK-JS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62373

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration. The class's `deserialize()` method uses Python's `pickle.loads()` on data received from WebSocket clients without any validation or sanitization. This means that a malicious WebSocket client can

PUBLISHED
Vendor
pipecat-ai
Product
pipecat
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62372

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of whether the model is intended to support such inputs (as defined in the Supported Models page). This issue has been patched in version 0.11.1.

PUBLISHED
Vendor
vllm-project
Product
vllm
Provider severity
HIGH
Conflicts
0

CVE-2025-62371

OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when connecting to OpenSearch clusters if no certificate path was explicitly configured. This behavior bypasses SSL certificate validation, potentially

PUBLISHED
Vendor
opensearch-project
Product
data-prepper
Provider severity
HIGH
Conflicts
0

CVE-2025-62370

Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible. The vulnerability was patched by a

PUBLISHED
Vendor
alloy-rs
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2025-6237

A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating the filename arguments, attackers can read and delete any files on the server, including critical system files such as SSH keys, databases, and configuration files. This vulnerability results in high confidentiality, integrity, and availability impacts.

PUBLISHED
Vendor
invoke-ai
Product
invoke-ai/invokeai
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62369

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 p

PUBLISHED
Vendor
xibosignage
Product
xibo-cms
Provider severity
HIGH
Conflicts
1

CVE-2025-62368

Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due to unsafe deserialization of untrusted data. This issue is fixed in version 6.9.0.

PUBLISHED
Vendor
taigaio
Product
taiga-back
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62367

Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-based blind SQL injection allowing sensitive data disclosure via response timing. This issue is fixed in version 6.9.0.

PUBLISHED
Vendor
taigaio
Product
taiga-back
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62366

mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions through 2.0.30 contain an HTML injection vulnerability in plaintext emails produced by the generatePlaintext method when user‑generated content is supplied. The function attempts to remove HTML tags, but if tags are provided as encoded HTML entities they are not removed and are later decoded, resulting in active HTML (for example an img tag with an event handler) in the supposed p

PUBLISHED
Vendor
eladnava
Product
mailgen
Provider severity
LOW
Conflicts
0

CVE-2025-62365

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` function was incorrectly use in a href environment), which caused the `project_issues` parameter to trigger an XSS vulnerability. This vulnerability is fixed in 25.7.0.

PUBLISHED
Vendor
librenms
Product
librenms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62364

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the application processes the upload, it follows the symbolic link and serves the contents of the targeted file through the web interface. This allows an unauthenticated attacker to read sensitive files on

PUBLISHED
Vendor
oobabooga
Product
text-generation-webui
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62363

yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executable via the path_to_yt_dlp configuration setting. An attacker with write access to the configuration file or the filesystem location of the configured executable can replace the executable with malicious code or create a symlink to an arbitrary executable. When the application invokes yt-dlp, the malicious code is execu

PUBLISHED
Vendor
zheny-creator
Product
YtGrabber-TUI
Provider severity
HIGH
Conflicts
0

CVE-2025-62362

gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information disclosure may violate employee privacy expectations and could be used for targeted attacks or unwanted contact. This issue has been patched in versions 2.0.3, 3.0.2, and 4.0.1. No known workarounds exi

PUBLISHED
Vendor
GPP-Woo
Product
GPP-burgerportaal
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62361

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified in the control.php endpoint of the WeGIA application, specifically in the nextPage parameter (metodo=listarTodos nomeClasse=AlmoxarifeControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This vulnerability is fix

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62360

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6236

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PUBLISHED
Vendor
Unknown
Product
Hostel
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62359

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /pet/profile_pet.php?id_pet= endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the id_pet parameter. This vulnerability is fixed in 3.5.0.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62358

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log parameter in configuracao_geral.php is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can inject arbitrary JavaScript, which executes in the victim’s browser. This vulnerability is fixed in 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62356

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.

PUBLISHED
Vendor
Qodo
Product
Qodo Gen
Provider severity
HIGH
Conflicts
0

CVE-2025-62354

Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code execution.

PUBLISHED
Vendor
cursor
Product
cursor
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62353

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection.

PUBLISHED
Vendor
Windsurf
Product
Windsurf
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6235

In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under specific interaction conditions. Successful exploitation could lead to exposure of user data or unauthorized actions within the browser context.

PUBLISHED
Vendor
Extreme Networks
Product
ExtremeControl
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62349

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

PUBLISHED
Vendor
Salt Project, Salt Project
Product
Salt, Salt
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-62348

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

PUBLISHED
Vendor
Salt Project, Salt Project
Product
Salt, Salt
Provider severity
HIGH
Conflicts
2

CVE-2025-62347

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.

PUBLISHED
Vendor
HCL
Product
HCL iControl
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62346

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious action on a trusted site where the user is authenticated, specifically on one endpoint.

PUBLISHED
Vendor
HCL Software
Product
Glovius Cloud
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the risk of misconfiguration and operational errors.

PUBLISHED
Vendor
HCL
Product
BigFix RunBookAI
Provider severity
LOW
Conflicts
0

CVE-2025-62340

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

PUBLISHED
Vendor
HCL Software
Product
iControl
Provider severity
LOW
Conflicts
0

CVE-2025-6234

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PUBLISHED
Vendor
Unknown
Product
Hostel
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62338

HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized access and may lead to information exposure.

PUBLISHED
Vendor
HCLSoftware
Product
BigFix Cloud Lifecycle Management
Provider severity
LOW
Conflicts
0

CVE-2025-62330

HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive monitoring or man-in-the-middle attacks.

PUBLISHED
Vendor
HCL Software
Product
DevOps Deploy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6233

Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62329

HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

PUBLISHED
Vendor
HCL Software
Product
DevOps Deploy / Launch
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62328

HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.

PUBLISHED
Vendor
HCLSoftware
Product
Nomad server on Domino
Provider severity
LOW
Conflicts
0

CVE-2025-62327

In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credential previously saved for performing authenticated LLM Queries.

PUBLISHED
Vendor
HCLSoftware
Product
DevOps Deploy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62326

HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.

PUBLISHED
Vendor
HCLSoftware
Product
Digital Experience
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62320

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in that HTML, which can cause unexpected requests from the user’s browser.

PUBLISHED
Vendor
HCL
Product
Sametime
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6232

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying specific registry locations.

PUBLISHED
Vendor
Lenovo, Lenovo
Product
Commercial Vantage, Vantage
Provider severity
HIGH
Conflicts
2

CVE-2025-62319

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.

PUBLISHED
Vendor
HCL
Product
Unica
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary systems, potentially leading to unintended information disclosure under certain conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
LOW
Conflicts
0

CVE-2025-62316

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under specific conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
LOW
Conflicts
0

CVE-2025-62313

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
LOW
Conflicts
0

CVE-2025-62311

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62310

HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized access under specific conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6231

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.

PUBLISHED
Vendor
Lenovo, Lenovo
Product
Vantage, Commercial Vantage
Provider severity
HIGH
Conflicts
2

CVE-2025-62309

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to unintended exposure under specific conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
LOW
Conflicts
0

CVE-2025-62308

HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details, which may potentially assist in further analysis or targeted actions under certain conditions

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62305

HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allow exposure of data to external systems under specific conditions.

PUBLISHED
Vendor
HCL
Product
AION
Provider severity
MEDIUM
Conflicts
0