CVE / JVNDB Latest 100

IDDescriptionSeverity
CVE-2025-7195
2025-12-06 14:02:49 UTC

Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

MEDIUM
5.2
CVE-2025-14136
2025-12-06 13:02:06 UTC

Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow

HIGH
8.7
CVE-2025-14135
2025-12-06 11:32:07 UTC

Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wired_clientlist_setClientsName stack-based overflow

HIGH
8.7
CVE-2025-14134
2025-12-06 11:02:07 UTC

Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow

HIGH
8.7
CVE-2025-14133
2025-12-06 10:32:05 UTC

Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wireless_clientlist_setClientsName stack-based overflow

HIGH
8.7
CVE-2025-14126
2025-12-06 10:02:05 UTC

TOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentials

HIGH
8.7
CVE-2025-12966
2025-12-06 09:25:58 UTC

All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP

HIGH
8.8
CVE-2025-13065
2025-12-06 09:25:58 UTC

Starter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass

HIGH
8.8
CVE-2025-12499
2025-12-06 07:29:12 UTC

Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google Review

HIGH
7.2
CVE-2025-13377
2025-12-06 06:39:09 UTC

10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache

CRITICAL
9.6
CVE-2025-13748
2025-12-06 06:39:09 UTC

Fluent Forms <= 6.1.7 - Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id

MEDIUM
5.3
CVE-2025-13309
2025-12-06 05:49:36 UTC

Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters <= 1.0.0 - Authenticated (Subscriber+) Missing Authorization to Modify Accessibility Settings

MEDIUM
4.3
CVE-2025-13358
2025-12-06 05:49:36 UTC

Accessiy By CodeConfig Accessibility <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Page Creation

MEDIUM
5.3
CVE-2025-12091
2025-12-06 05:49:35 UTC

Search, Filters & Merchandising for WooCommerce <= 3.0.63 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation

MEDIUM
4.3
CVE-2025-13894
2025-12-06 05:49:35 UTC

CSV Sumotto <= 1.0 - Reflected Cross-Site Scripting

MEDIUM
6.1
CVE-2025-13857
2025-12-06 05:49:34 UTC

Yet Another WebClap for WordPress <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

MEDIUM
6.4
CVE-2025-13856
2025-12-06 05:49:33 UTC

Extra Post Images <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

MEDIUM
6.4
CVE-2025-13863
2025-12-06 05:49:33 UTC

RevInsite <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

MEDIUM
6.4
CVE-2025-12717
2025-12-06 05:49:32 UTC

List Attachments Shortcode <= 0.4.1a - Authenticated (Author+) Stored Cross-Site Scripting via list-attachments Shortcode

MEDIUM
6.4
CVE-2025-13907
2025-12-06 05:49:32 UTC

CSS3 Buttons <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

MEDIUM
6.4
CVE-2025-12577
2025-12-06 05:49:31 UTC

Listar – Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Listing Update

MEDIUM
4.3
CVE-2025-12715
2025-12-06 05:49:30 UTC

Canadian Nutrition Facts Label <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Nutrition Label Custom Post Type

MEDIUM
6.4
CVE-2025-13656
2025-12-06 05:49:30 UTC

Cute News Ticker <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute

MEDIUM
6.4
CVE-2025-13899
2025-12-06 05:49:29 UTC

TR Timthumb <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

MEDIUM
6.4
CVE-2025-13308
2025-12-06 05:49:28 UTC

Application Passwords <= 0.1.3 - Reflected Cross-Site Scripting via reject_url

MEDIUM
5.4
CVE-2025-13666
2025-12-06 05:49:27 UTC

Helloprint <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification

MEDIUM
5.3
CVE-2025-12673
2025-12-06 05:49:26 UTC

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload

CRITICAL
9.8
CVE-2025-13629
2025-12-06 05:49:26 UTC

WP Landing Page <= 0.9.3 - Cross-Site Request Forgery to Arbitrary Post Meta Update

MEDIUM
4.3
CVE-2025-12574
2025-12-06 05:49:25 UTC

Listar – Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

MEDIUM
4.3
CVE-2025-12720
2025-12-06 05:49:25 UTC

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

MEDIUM
5.3
CVE-2025-12721
2025-12-06 05:49:24 UTC

g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

MEDIUM
5.3
CVE-2025-13896
2025-12-06 05:49:23 UTC

Social Feed Gallery Portfolio <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute

MEDIUM
6.4
CVE-2025-13137
2025-12-06 05:49:22 UTC

Live Sales Notification for Woocommerce – Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting

MEDIUM
6.1
CVE-2025-13898
2025-12-06 05:49:22 UTC

Ultra Skype Button <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_id' Shortcode Attribute

MEDIUM
6.4
CVE-2025-13626
2025-12-06 05:49:21 UTC

myLCO <= 0.8.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']

MEDIUM
6.1
CVE-2025-14117
2025-12-06 05:32:06 UTC

fit2cloud Halo cross-site request forgery

MEDIUM
5.3
CVE-2025-13292
2025-12-06 05:05:52 UTC

Improper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.

HIGH
7.6
CVE-2025-66644
2025-12-06 04:55:51 UTC

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

HIGH
7.2
CVE-2025-12196
2025-12-06 04:55:50 UTC

WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command

HIGH
8.6
CVE-2025-12026
2025-12-06 04:55:48 UTC

WatchGuard Firebox Authenticated Out of Bounds Write in certd

HIGH
8.6
CVE-2025-12195
2025-12-06 04:55:47 UTC

WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration

HIGH
8.6
CVE-2025-1910
2025-12-06 04:55:45 UTC

WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package

MEDIUM
6.3
CVE-2025-1547
2025-12-06 04:55:44 UTC

WatchGuard Firebox Authenticated Stack Overflow in Certificate Request Command

HIGH
7.5
CVE-2025-55182
2025-12-06 04:55:43 UTC

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CRITICAL
10.0
CVE-2025-13922
2025-12-06 04:37:51 UTC

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause

MEDIUM
6.5
CVE-2025-12505
2025-12-06 04:37:50 UTC

weDocs <= 2.1.14 - Missing Authorization to Settings Update

MEDIUM
5.4
CVE-2025-40217
2025-12-06 04:14:42 UTC

pidfs: validate extensible ioctls

CVE-2025-40195
2025-12-06 04:14:39 UTC

mount: handle NULL values in mnt_ns_release()

CVE-2024-42130
2025-12-06 04:14:36 UTC

nfc/nci: Add the inconsistency check between the input data length and count

CVE-2024-35929
2025-12-06 04:14:34 UTC

rcu/nocb: Fix WARN_ON_ONCE() in the rcu_nocb_bypass_lock()

CVE-2022-49129
2025-12-06 04:14:31 UTC

mt76: mt7921: fix crash when startup fails.

HIGH
7.8
CVE-2021-47295
2025-12-06 04:14:28 UTC

net: sched: fix memory leak in tcindex_partial_destroy_work

HIGH
7.5
CVE-2025-65844
2025-12-06 03:51:57 UTC

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

HIGH
7.5
CVE-2025-11263
2025-12-06 03:27:05 UTC

Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting

MEDIUM
6.1
CVE-2025-12510
2025-12-06 03:27:04 UTC

Widgets for Google Reviews <= 13.2.4 - Unauthenticated Stored Cross-Site Scripting via Google Reviews

HIGH
7.2
CVE-2025-59820
2025-12-06 02:32:11 UTC

In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.

MEDIUM
6.7
CVE-2024-3884
2025-12-06 00:07:44 UTC

Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

HIGH
7.5
CVE-2025-23367
2025-12-06 00:07:32 UTC

Org.wildfly.core:wildfly-server: wildfly improper rbac permission

MEDIUM
6.5
CVE-2025-65955
2025-12-05 23:53:17 UTC

Further research determined the issue is not a vulnerability.

MEDIUM
4.9
CVE-2025-66629
2025-12-05 22:47:45 UTC

HedgeDoc is missing state parameter in OAuth2 flows could lead to CSRF

LOW
3.7
CVE-2025-14116
2025-12-05 22:32:08 UTC

xerrors Yuxi-Know embed.py OtherEmbedding.aencode server-side request forgery

MEDIUM
5.1
CVE-2025-14111
2025-12-05 22:32:05 UTC

Rarlab RAR App com.rarlab.rar path traversal

LOW
2.3
CVE-2025-34291
2025-12-05 22:27:26 UTC

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

CRITICAL
9.4
CVE-2025-14108
2025-12-05 22:02:05 UTC

ZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injection

HIGH
8.7
CVE-2025-57213
2025-12-05 21:57:05 UTC

Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

HIGH
7.5
CVE-2025-57212
2025-12-05 21:56:06 UTC

Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

HIGH
7.5
CVE-2025-57210
2025-12-05 21:54:41 UTC

Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified vectors.

HIGH
7.5
CVE-2025-65637
2025-12-05 21:53:00 UTC

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions < 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.

HIGH
7.5
CVE-2025-29269
2025-12-05 21:51:33 UTC

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

MEDIUM
6.5
CVE-2025-64052
2025-12-05 21:49:56 UTC

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

MEDIUM
5.1
CVE-2025-8148
2025-12-05 21:48:44 UTC

CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT

MEDIUM
4.2
CVE-2025-14105
2025-12-05 21:48:08 UTC

TOZED ZLT M30S/ZLT M30S PRO Web proc_post denial of service

MEDIUM
5.3
CVE-2025-13426
2025-12-05 21:46:35 UTC

Improper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code Execution

HIGH
8.7
CVE-2025-14106
2025-12-05 21:45:51 UTC

ZSPACE Q2C NAS HTTP POST Request close zfilev2_api.CloseSafe command injection

HIGH
8.7
CVE-2025-14107
2025-12-05 21:44:56 UTC

ZSPACE Q2C NAS HTTP POST Request status zfilev2_api.SafeStatus command injection

HIGH
8.7
CVE-2025-63363
2025-12-05 21:08:01 UTC

A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation frames to be broadcast without authentication or encryption.

HIGH
7.5
CVE-2025-63361
2025-12-05 21:03:55 UTC

Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator password in plaintext.

MEDIUM
5.7
CVE-2025-65897
2025-12-05 20:49:47 UTC

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the server file system, potentially overwriting existing files and leading to privilege escalation or remote code execution.

HIGH
8.8
CVE-2025-65900
2025-12-05 20:30:46 UTC

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission validation and excessive data exposure in the backend, an authenticated user with basic read permissions can retrieve sensitive information for all platform users.

MEDIUM
6.5
CVE-2025-13836
2025-12-05 20:30:25 UTC

Excessive read buffering DoS in http.client

MEDIUM
6.3
CVE-2025-12084
2025-12-05 20:30:20 UTC

Quadratic complexity in node ID cache clearing

MEDIUM
6.3
CVE-2025-66624
2025-12-05 20:10:58 UTC

BACnet-stack MS/TP reply matcher OOB read

HIGH
7.5
CVE-2025-66623
2025-12-05 20:10:26 UTC

Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands

HIGH
7.4
CVE-2025-66581
2025-12-05 20:09:53 UTC

Frappe LMS is Missing Server-Side Authorization in Business Logic

LOW
1.3
CVE-2025-34265
2025-12-05 20:09:22 UTC

Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines

MEDIUM
5.1
CVE-2025-65868
2025-12-05 20:09:16 UTC

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

CRITICAL
9.1
CVE-2020-36879
2025-12-05 20:08:50 UTC

Flexsense DiskBoss Service Unquoted Service Path Vulnerability

HIGH
8.5
CVE-2025-34263
2025-12-05 20:08:20 UTC

Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/dashboards/menus

MEDIUM
5.1
CVE-2025-64055
2025-12-05 20:08:07 UTC

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

CRITICAL
9.8
CVE-2020-36878
2025-12-05 20:07:45 UTC

ReQuest Serious Play F3 Media Player <= 3.0.0 Directory Traversal File Disclosure

HIGH
8.7
CVE-2020-36876
2025-12-05 20:07:15 UTC

ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020

HIGH
8.7
CVE-2025-53963
2025-12-05 20:06:54 UTC

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can achieve root code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CRITICAL
9.8
CVE-2025-14094
2025-12-05 20:06:33 UTC

Edimax BR-6478AC V3 formSysCmd sub_44CCE4 os command injection

MEDIUM
5.1
CVE-2024-9183
2025-12-05 20:05:57 UTC

Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

HIGH
7.7
CVE-2025-54303
2025-12-05 20:05:35 UTC

The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a password change policy for default administrative accounts is not enforced. Many deployments may retain default credentials, in which case an attacker is likely to be able to successfully authenticate with administrative privileges.

CRITICAL
9.8
CVE-2025-66512
2025-12-05 20:05:05 UTC

Nextcloud Server vulnerable to XSS in SVG images when opened outside of Nextcloud

MEDIUM
5.4
CVE-2025-54304
2025-12-05 20:03:49 UTC

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127.0.0.1 and 192.168.2.15. If a device is powered on and later connected to a network with DHCP, the device may not be assigned the 192.168.2.15 IP address, leaving the display server accessible by other devices on the network. The exposed X11 display server can then be used to gain root privileges and the ability to execute code remotely by interacting with matchbox-desktop and spawning a terminal. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CRITICAL
9.8
CVE-2025-65879
2025-12-05 20:03:40 UTC

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authenticated attacker can delete arbitrary files on the server by supplying directory traversal payloads.

HIGH
8.1
CVE-2025-14104
2025-12-05 20:03:20 UTC

Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames

MEDIUM
6.1
CVE-2025-66510
2025-12-05 20:02:54 UTC

Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list

MEDIUM
4.5