Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62237

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” text field.

PUBLISHED
Vendor
Liferay, Liferay
Product
DXP, Portal
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62236

The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.

PUBLISHED
Vendor
Frontier Airlines
Product
flyfrontier.com
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62235

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Mynewt NimBLE
Provider severity
HIGH
Conflicts
0

CVE-2025-62233

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62232

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:  https://github.com/apache/apisix/pull/12629 Users are recommended to upgrade to version 3.14, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
HIGH
Conflicts
0

CVE-2025-62231

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, X.Org, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10, Xwayland, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Provider severity
HIGH
Conflicts
1

CVE-2025-62230

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, X.Org, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Xwayland, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Provider severity
HIGH
Conflicts
1

CVE-2025-62229

A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error handling during notification creation can leave dangling pointers that lead to a use-after-free condition. This can cause memory corruption or a crash, potentially allowing an attacker to execute arbitrary code or cause a denial of service.

PUBLISHED
Vendor
X.Org, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Xwayland, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support
Provider severity
HIGH
Conflicts
1

CVE-2025-62228

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62225

Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

PUBLISHED
Vendor
Sony Corporation
Product
Optical Disc Archive Software (for Windows)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-62224

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge for Android
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62223

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Visual Studio Code CoPilot Chat Extension
Provider severity
HIGH
Conflicts
1

CVE-2025-62221

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62220

Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Subsystem for Linux GUI
Provider severity
HIGH
Conflicts
0

CVE-2025-6222

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
WP Swings
Product
WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62219

Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2025-62218

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2025-62217

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2016, Windows 11 Version 23H2, Windows Server 2008 Service Pack 2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows Server 2022, Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2025-62216

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2025-62215

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2022, Windows 11 version 22H3, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2025-62214

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Visual Studio 2022 version 17.14
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62213

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2016, Windows 11 Version 24H2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2025-62211

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Dynamics 365 Field Service (online)
Provider severity
HIGH
Conflicts
0

CVE-2025-62210

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Dynamics 365 Field Service (online)
Provider severity
HIGH
Conflicts
0

CVE-2025-6221

The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
luuptek
Product
Embed Bokun
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62209

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 22H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1507
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62208

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 11 version 22H2, Windows 11 Version 24H2, Windows 10 Version 1507, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2016, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 1607
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62207

Azure Monitor Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor Control Service
Provider severity
HIGH
Conflicts
0

CVE-2025-62206

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics 365 (on-premises) version 9.1
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62205

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2025-62204

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2025-62203

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Office Online Server, Microsoft Excel 2016, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2025-62202

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office Online Server, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2025-62201

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Excel 2016
Provider severity
HIGH
Conflicts
1

CVE-2025-62200

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Excel 2016, Office Online Server, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2025-6220

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PUBLISHED
Vendor
themefic
Product
Ultra Addons for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2025-62199

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office for Android, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2025-62198

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Atlas
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62193

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tmap.las.filter.RequestInputFilter.java' from 2025-09-24.

PUBLISHED
Vendor
National Oceanic and Atmospheric Administration (NOAA)
Product
Live Access Server (LAS)
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62192

SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If exploited, information stored in the database may be obtained or altered by an authenticated user.

PUBLISHED
Vendor
Japan Total System Co.,Ltd., Japan Total System Co.,Ltd., Japan Total System Co.,Ltd.
Product
GroupSession Free edition, GroupSession byCloud, GroupSession ZION
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62190

Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62189

LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.

PUBLISHED
Vendor
LogStare Inc., LogStare Inc.
Product
LogStare Collector (for Windows), LogStare Collector (for Linux)
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62188

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade to: * version ≥ 3.2.0 if using 3.1.x As a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
HIGH
Conflicts
0

CVE-2025-62187

In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).

PUBLISHED
Vendor
Ankitects
Product
Anki
Provider severity
LOW
Conflicts
0

CVE-2025-62186

Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.

PUBLISHED
Vendor
Ankitects
Product
Anki
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62185

In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.

PUBLISHED
Vendor
Ankitects
Product
Anki
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62184

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.

PUBLISHED
Vendor
Pegasystems
Product
Pega Infinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62183

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.

PUBLISHED
Vendor
Pegasystems
Product
Pega Infinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62182

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.

PUBLISHED
Vendor
Pegasystems
Product
Pega Infinity
Provider severity
MEDIUM
Conflicts
0