Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62181

Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication feature and other more secure authentication mechanisms are recommended. A fix is being provided in the 24.1.4, 24.2.4, and 25.1.1 patch releases. Please note: Basic credentials

PUBLISHED
Vendor
Pegasystems
Product
Pega Infinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.

PUBLISHED
Vendor
Pegasystems
Product
Pega Infinity
Provider severity
HIGH
Conflicts
0

CVE-2025-6218

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can lever

PUBLISHEDCISA KEV
Vendor
RARLAB
Product
WinRAR
Provider severity
HIGH
Conflicts
0

CVE-2025-62179

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php endpoint, specifically in the cpf parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
HIGH
Conflicts
0

CVE-2025-62178

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /html/atendido/cadastro_atendido_parentesco_pessoa_nova.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the idatendido parameter. This vulnerability is fixed in 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
LOW
Conflicts
0

CVE-2025-62177

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar.php endpoint, specifically in the id_funcionario parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

PUBLISHED
Vendor
LabRedesCefetRJ
Product
WeGIA
Provider severity
HIGH
Conflicts
0

CVE-2025-62176

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for public timelines to clients using any valid authentication token, even if those tokens lack the read:statuses scope. This allows OAuth clients without the read scope to subscribe to public channels and receive public timeline events. The impact is limited, as this only affects new public posts published on the public timelines a

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62175

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnect the account from the streaming API. This allows disabled or suspended accounts to continue receiving real-time updates through existing streaming connections and to establish new streaming connections, even though they cannot interact with other API endpoints. This undermines moderation actions, as administrators expe

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62174

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's password via the command-line interface using `bin/tootctl accounts modify --reset-password`, active sessions and access tokens for that account are not revoked. This allows an attacker with access to a previously compromised session or token to continue using the account after the password has been reset. This issue has been pat

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
LOW
Conflicts
0

CVE-2025-62173

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

PUBLISHED
Vendor
FreePBX
Product
restapps
Provider severity
HIGH
Conflicts
0

CVE-2025-62172

Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field, which is then executed when any user hovers over data points in the energy dashboard graph tooltips. The vulnerability exists because entity names containing HTML are not properly sanitized before bei

PUBLISHED
Vendor
home-assistant
Product
core
Provider severity
HIGH
Conflicts
1

CVE-2025-62171

ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wra

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62170

rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality of rAthena's map-server in versions prior to commit af2f3ba. An unauthenticated attacker can exploit this vulnerability via a specific attacking scenario to cause a denial of service by crashing the map-server. This issue has been patched in commit af2f3ba. There are no known workarounds aside from manually applying the patch.

PUBLISHED
Vendor
rathena
Product
rathena
Provider severity
HIGH
Conflicts
0

CVE-2025-6217

PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of PEAK-System Driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the PCANFD_ADD_FILTERS IOCTL. The issue results from the lack of proper locking when perfo

PUBLISHED
Vendor
PEAK-System
Product
Driver
Provider severity
LOW
Conflicts
0

CVE-2025-62169

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. This issue has been patched in versions 1.8.0a3 of the testing branch and 1.7.8 of the stable branch. The impact of this vulnerability is greatly reduced when using OctoPrint version 1.11.2 and newer.

PUBLISHED
Vendor
WildRikku
Product
OctoPrint-SpoolManager
Provider severity
HIGH
Conflicts
0

CVE-2025-62168

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify security tokens or credentials used internally by a web application using Squid for backend load balancing. These attacks do not require Sq

PUBLISHED
Vendor
squid-cache
Product
squid
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62166

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.

PUBLISHED
Vendor
FreshRSS
Product
FreshRSS
Provider severity
HIGH
Conflicts
1

CVE-2025-62164

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When processing user-supplied prompt embeddings, the endpoint loads serialized tensors using torch.load() without sufficient validation. Due to a change introduced in PyTorch 2.8.0, sparse tensor integrity checks are disabled

PUBLISHED
Vendor
vllm-project
Product
vllm
Provider severity
HIGH
Conflicts
1

CVE-2025-62162

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can cause the parser to panic, terminating the process. When the crate is used to evaluate untrusted expressions (e.g., user-supplied input over an API), an attacker can send crafted input to trigger a denial of service (DoS). Version 0.11.4 fixes the issue.

PUBLISHED
Vendor
cel-rust
Product
cel-rust
Provider severity
HIGH
Conflicts
0

CVE-2025-62161

Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/null is insufficient, allowing container escape when youki utilizes bind mounting the container's /dev/null as a file mask. This issue is fixed in version 0.5.7.

PUBLISHED
Vendor
youki-dev
Product
youki
Provider severity
HIGH
Conflicts
1

CVE-2025-6216

Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password recovery mechanism. The issue results from reliance upon a predictable value when generating a password reset token. An attacker can leverage this vulnerability to bypass authentication on the applicat

PUBLISHED
Vendor
Allegra
Product
Allegra
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62159

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider previously retrieved Kubernetes secrets directly, without validating the namespace context or the type of secret store. This allowed unauthorized cross-namespace secret access, violating security boundaries and potential

PUBLISHED
Vendor
external-secrets
Product
external-secrets
Provider severity
HIGH
Conflicts
0

CVE-2025-62158

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access these files without authentication. The issue has been fixed in version 2.38.0 by ensuring all student-uploaded assignment attachments are stored as private files by default.

PUBLISHED
Vendor
frappe
Product
lms
Provider severity
LOW
Conflicts
0

CVE-2025-62157

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. An attacker with permissions to read pod logs in a namespace running Argo Workflows can read the workflow-controller logs and obtain credentials to the artifact repository. Update to versions 3.6.12 or 3.7.3 to remediate the vuln

PUBLISHED
Vendor
argoproj
Product
argo-workflows
Provider severity
HIGH
Conflicts
0

CVE-2025-62156

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain a Zip Slip path traversal vulnerability in artifact extraction. During artifact extraction the unpack/untar logic (workflow/executor/executor.go) uses filepath.Join(dest, filepath.Clean(header.Name)) without validating that header.Name stays within the intended extraction directory. A malicious archive entry can supply

PUBLISHED
Vendor
argoproj
Product
argo-workflows
Provider severity
HIGH
Conflicts
0

CVE-2025-62155

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and still allow SSRF to occur. Because the existing fix only applies security restrictions to the first URL request, a 302 redirect can bypass existing security measures and successfully access the intranet. This issue has been patched in version 0.9.6.

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
HIGH
Conflicts
0

CVE-2025-62154

Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One ai-content-writing-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One: from n/a through <= 1.1.7.

PUBLISHED
Vendor
recorp
Product
AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in One
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62153

Missing Authorization vulnerability in Graham Quick Interest Slider quick-interest-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Interest Slider: from n/a through <= 3.1.7.

PUBLISHED
Vendor
Graham
Product
Quick Interest Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62152

Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.2.

PUBLISHED
Vendor
ConveyThis
Product
ConveyThis
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62151

Missing Authorization vulnerability in Virtuaria Virtuaria PagBank / PagSeguro para Woocommerce virtuaria-pagseguro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Virtuaria PagBank / PagSeguro para Woocommerce: from n/a through <= 3.6.3.

PUBLISHED
Vendor
Virtuaria
Product
Virtuaria PagBank / PagSeguro para Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62150

Missing Authorization vulnerability in themesawesome History Timeline timeline-awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects History Timeline: from n/a through <= 1.0.6.

PUBLISHED
Vendor
themesawesome
Product
History Timeline
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6215

The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to the public (permission_callback always returns true) and invokes wp_create_user() unconditionally, ignoring the site’s users_can_register option and any nonce or CAPTCHA checks. This makes it possible for unauthenticated attackers to create arbitrary user accounts (customer) on sites where registrations should be closed.

PUBLISHED
Vendor
omnishop
Product
Omnishop – Mobile shop apps complementing your WooCommerce webshop
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62149

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Stored XSS.This issue affects Add Custom Codes: from n/a through <= 4.80.

PUBLISHED
Vendor
SaifuMak
Product
Add Custom Codes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62148

Cross-Site Request Forgery (CSRF) vulnerability in Eugen Bobrowski Robots.txt rewrite robotstxt-rewrite allows Cross Site Request Forgery.This issue affects Robots.txt rewrite: from n/a through <= 1.6.1.

PUBLISHED
Vendor
Eugen Bobrowski
Product
Robots.txt rewrite
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62147

Missing Authorization vulnerability in nikmelnik Realbig realbig-media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Realbig: from n/a through <= 1.1.3.

PUBLISHED
Vendor
nikmelnik
Product
Realbig
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62146

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1.

PUBLISHED
Vendor
Maksym Marko
Product
MX Time Zone Clocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62145

Missing Authorization vulnerability in NewClarity DMCA Protection Badge dmca-badge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DMCA Protection Badge: from n/a through <= 2.2.0.

PUBLISHED
Vendor
NewClarity
Product
DMCA Protection Badge
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62144

Missing Authorization vulnerability in Mohammed Kaludi Core Web Vitals & PageSpeed Booster core-web-vitals-pagespeed-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Core Web Vitals & PageSpeed Booster: from n/a through <= 1.0.28.

PUBLISHED
Vendor
Mohammed Kaludi
Product
Core Web Vitals & PageSpeed Booster
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62143

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in nicashmu Post Video Players video-playlist-and-gallery-plugin allows Retrieve Embedded Sensitive Data.This issue affects Post Video Players: from n/a through <= 1.163.

PUBLISHED
Vendor
nicashmu
Product
Post Video Players
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62142

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicashmu Post Video Players video-playlist-and-gallery-plugin allows Stored XSS.This issue affects Post Video Players: from n/a through <= 1.163.

PUBLISHED
Vendor
nicashmu
Product
Post Video Players
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62141

Missing Authorization vulnerability in Information Technology Wawp automation-web-platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wawp: from n/a through <= 4.4.

PUBLISHED
Vendor
Information Technology
Product
Wawp
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62140

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68.

PUBLISHED
Vendor
plainware
Product
Locatoraid Store Locator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6214

The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The route’s permission_callback only verifies that the requester is logged in, but fails to require any nonce or other proof of intent. This makes it possible for unauthenticated attackers to delete arbitrary user accounts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
omnishop
Product
Omnishop – Mobile shop apps complementing your WooCommerce webshop
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62139

Insertion of Sensitive Information Into Sent Data vulnerability in Vladimir Statsenko Terms descriptions terms-descriptions allows Retrieve Embedded Sensitive Data.This issue affects Terms descriptions: from n/a through <= 3.4.10.

PUBLISHED
Vendor
Vladimir Statsenko
Product
Terms descriptions
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62138

Missing Authorization vulnerability in cedcommerce WP Advanced PDF wp-advanced-pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Advanced PDF: from n/a through <= 1.1.7.

PUBLISHED
Vendor
cedcommerce
Product
WP Advanced PDF
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62137

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shuttlethemes Shuttle shuttle allows Stored XSS.This issue affects Shuttle: from n/a through <= 1.5.0.

PUBLISHED
Vendor
shuttlethemes
Product
Shuttle
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62136

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Melos melos allows Stored XSS.This issue affects Melos: from n/a through <= 1.6.0.

PUBLISHED
Vendor
thinkupthemes
Product
Melos
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62135

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in landwire Responsive Block Control responsive-block-control allows DOM-Based XSS.This issue affects Responsive Block Control: from n/a through <= 1.3.0.

PUBLISHED
Vendor
landwire
Product
Responsive Block Control
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62134

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through <= 1.5.1.

PUBLISHED
Vendor
A WP Life
Product
Contact Form Widget
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62133

Cross-Site Request Forgery (CSRF) vulnerability in manidoraisamy FormFacade formfacade allows Cross Site Request Forgery.This issue affects FormFacade: from n/a through <= 1.4.1.

PUBLISHED
Vendor
manidoraisamy
Product
FormFacade
Provider severity
MEDIUM
Conflicts
0