Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-61994

Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.

PUBLISHED
Vendor
GROWI, Inc.
Product
GROWI
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61990

When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5, F5, F5
Product
BIG-IP, BIG-IP Next CNF, BIG-IP Next for Kubernetes, BIG-IP Next SPK
Provider severity
HIGH
Conflicts
2

CVE-2025-6199

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10
Provider severity
LOW
Conflicts
1

CVE-2025-61987

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be exposed.

PUBLISHED
Vendor
Japan Total System Co.,Ltd., Japan Total System Co.,Ltd., Japan Total System Co.,Ltd.
Product
GroupSession Free edition, GroupSession ZION, GroupSession byCloud
Provider severity
MEDIUM
Conflicts
2

CVE-2025-61985

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, OpenBSD
Product
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, OpenSSH
Provider severity
LOW
Conflicts
1

CVE-2025-61984

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

PUBLISHED
Vendor
OpenBSD, Siemens, Siemens, Siemens, Siemens, Siemens
Product
OpenSSH, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Provider severity
LOW
Conflicts
1

CVE-2025-61983

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing an excessive number of fields with zero‑length values.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Archer AX53 v1.0
Provider severity
HIGH
Conflicts
0

CVE-2025-61982

An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM simulation file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

PUBLISHED
Vendor
OpenCFD
Product
OpenFOAM
Provider severity
HIGH
Conflicts
0

CVE-2025-6198

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.

PUBLISHED
Vendor
SMCI
Product
X13SEM-F
Provider severity
HIGH
Conflicts
0

CVE-2025-61979

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

PUBLISHED
Vendor
Canva
Product
Affinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-61977

A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.

PUBLISHED
Vendor
AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect
Product
Productivity 3000 P3-530 CPU, Productivity 3000 P3-550E CPU, Productivity 2000 P2-550 CPU, Productivity 1000 P1-540 CPU, Productivity Suite, Productivity 2000 P2-622 CPU, Productivity 3000 P3-622 CPU, Productivity 1000 P1-550 CPU
Provider severity
HIGH
Conflicts
2

CVE-2025-61976

CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a remote attacker sends a specially crafted request to the Video Download interface, the system may become unresponsive.

PUBLISHED
Vendor
Inaba Denki Sangyo Co., Ltd.
Product
CHOCO TEI WATCHER mini (IB-MCT001)
Provider severity
HIGH
Conflicts
1

CVE-2025-61974

When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5, F5, F5
Product
BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes
Provider severity
HIGH
Conflicts
2

CVE-2025-61973

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

PUBLISHED
Vendor
Epic Games
Product
Epic Games Store
Provider severity
HIGH
Conflicts
0

CVE-2025-61972

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD, AMD, AMD, AMD
Product
AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo"), AMD EPYC™ 9005 Series Processors, AMD EPYC™ 8004 Series Processors, AMD EPYC™ Embedded 8004 Series Processors, AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa"), AMD EPYC™ 9004 Series Processors, AMD EPYC™ Embedded 9005 Series Processors
Provider severity
HIGH
Conflicts
1

CVE-2025-61971

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.

PUBLISHED
Vendor
AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD, AMD
Product
AMD EPYC™ Embedded 7003 Series Processors, AMD EPYC™ Embedded 9005 Series Processors, AMD EPYC™ 7003 Series Processors, AMD EPYC™ Embedded 8004 Series Processors, AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa"), AMD EPYC™ 9005 Series Processors, AMD EPYC™ 9004 Series Processors, AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo"), AMD EPYC™ 8004 Series Processors
Provider severity
MEDIUM
Conflicts
1

CVE-2025-6197

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

PUBLISHED
Vendor
Grafana
Product
Grafana
Provider severity
MEDIUM
Conflicts
0

CVE-2025-61969

Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

PUBLISHED
Vendor
AMD
Product
AMD µProf
Provider severity
HIGH
Conflicts
0

CVE-2025-61962

In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed context.

PUBLISHED
Vendor
fetchmail
Product
fetchmail
Provider severity
MEDIUM
Conflicts
0

CVE-2025-61960

When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2025-6196

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content coul

PUBLISHED
Vendor
Red Hat
Product
Red Hat Enterprise Linux 7
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61959

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.

PUBLISHED
Vendor
Vertikal Systems
Product
Hospital Manager Backend Services
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61958

A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-61956

Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.

PUBLISHED
Vendor
Radiometrics
Product
VizAir
Provider severity
CRITICAL
Conflicts
1

CVE-2025-61955

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
F5OS - Appliance, F5OS - Chassis
Provider severity
HIGH
Conflicts
2

CVE-2025-61952

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

PUBLISHED
Vendor
Canva
Product
Affinity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-61951

Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a certificate, key, and the SSL Sign Hash set to ANY, and the backend server is enabled with DTLS 1.2 and client authentication.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2025-61950

In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is improperly implemented. With some crafted request, a logged-in user may alter the memo field. The affected products and versions are GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2.

PUBLISHED
Vendor
Japan Total System Co.,Ltd., Japan Total System Co.,Ltd., Japan Total System Co.,Ltd.
Product
GroupSession ZION, GroupSession byCloud, GroupSession Free edition
Provider severity
MEDIUM
Conflicts
2

CVE-2025-6195

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2025-61949

LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.

PUBLISHED
Vendor
LogStare Inc., LogStare Inc.
Product
LogStare Collector (for Linux), LogStare Collector (for Windows)
Provider severity
MEDIUM
Conflicts
2

CVE-2025-61945

Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and flight safety. This unauthorized access could result in the disabling of vital alerts, causing hazardous conditions for aircraft, and manipulating runway assignments, which could result

PUBLISHED
Vendor
Radiometrics
Product
VizAir
Provider severity
CRITICAL
Conflicts
1

CVE-2025-61944

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing an excessive number of fields with zero‑length values.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Archer AX53 v1.0
Provider severity
HIGH
Conflicts
0

CVE-2025-61943

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.

PUBLISHED
Vendor
AVEVA
Product
Process Optimization
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2025-61941

A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered by an administrative user who logs in to the affected product. Moreover, arbitrary OS command may be executed via some file alteration.

PUBLISHED
Vendor
BUFFALO INC.
Product
WXR9300BE6P series
Provider severity
HIGH
Conflicts
1

CVE-2025-61940

NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is restricted by a password authentication check in the client software but the underlying database connection always has access. The latest version of NMIS/BioDose introduces an option to use Windows user authentication with the database, which would restrict this database connection.

PUBLISHED
Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
Provider severity
HIGH
Conflicts
1

CVE-2025-61939

An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection to an attacker controlled device.

PUBLISHED
Vendor
Columbia Weather Systems
Product
MicroServer
Provider severity
HIGH
Conflicts
1

CVE-2025-61938

When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2025-61937

The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the  model application server.

PUBLISHED
Vendor
AVEVA
Product
Process Optimization
Provider severity
CRITICAL
Conflicts
1

CVE-2025-61935

When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2025-61934

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read, write, or delete arbitrary files and folders on the target machine

PUBLISHED
Vendor
AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect, AutomationDirect
Product
Productivity 2000 P2-622 CPU, Productivity 3000 P3-530 CPU, Productivity 3000 P3-622 CPU, Productivity 1000 P1-540 CPU, Productivity 1000 P1-550 CPU, Productivity 3000 P3-550E CPU, Productivity Suite, Productivity 2000 P2-550 CPU
Provider severity
CRITICAL
Conflicts
2

CVE-2025-61933

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61932

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.

PUBLISHEDCISA KEV
Vendor
MOTEX Inc.
Product
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA))
Provider severity
CRITICAL
Conflicts
1

CVE-2025-61931

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

PUBLISHED
Vendor
Implem Inc.
Product
Pleasanter
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61930

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change endpoint. An attacker can trick a logged‑in administrator into submitting a crafted POST request to change the admin password without consent. Impact is account takeover of privileged users. Severity: High. As of time of publication, no known patched versions exist.

PUBLISHED
Vendor
emlog
Product
emlog
Provider severity
HIGH
Conflicts
0

CVE-2025-6193

A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy a CR.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI 2.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61929

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded configuration data and directly executes the command within it. In the files `src/main/services/ProtocolClient.ts` and `src/main/services/urlschema/mcp-install.ts`, when receiving a URL of the `cherrystudio://mcp` type, the `handleMcpProtocolUrl` function is called for processing. If an

PUBLISHED
Vendor
CherryHQ
Product
cherry-studio
Provider severity
CRITICAL
Conflicts
0

CVE-2025-61928

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ?? (authRequired ? null : { id: ctx.body.userId })`. When no session exists but `userId` is present in the request body, `authRequired` becomes false and the user object is set to the attacker-controlled ID. Server-only field

PUBLISHED
Vendor
better-auth
Product
better-auth
Provider severity
CRITICAL
Conflicts
1

CVE-2025-61927

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerability that puts the owner system at the risk of RCE (Remote Code Execution) attacks. A Node.js VM Context is not an isolated environment, and if the user runs untrusted JavaScript code within the Happy DOM VM Context, it may escape the VM and get access to process level functionality. It seems like what the attacker can get control over depends on if

PUBLISHED
Vendor
capricorn86
Product
happy-dom
Provider severity
HIGH
Conflicts
0

CVE-2025-61926

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be validated against a hard-coded, shared secret. The value used for the secret token was compiled into the Allstar binary and could not be configured at runtime. In practice, this meant that every deployment using Reviewbot would validate requests with the same secret unless the operator modified source code and rebuilt the c

PUBLISHED
Vendor
ossf
Product
allstar
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61925

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is common for web servers such as nginx to route requests via the `Host` header, and forward on other request headers. As such as malicious request can be sent with both a `Host` header and an `X-Forwarded-Host` header where the values do not match and the `X-Forwarded-Host` header is malicious. Astro will then return the malicious value. T

PUBLISHED
Vendor
withastro
Product
astro
Provider severity
MEDIUM
Conflicts
0