Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2025-46707 Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU. | 5.2 | MEDIUM | — | 0 |
| CVE-2025-46708 Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU. | 4.3 | MEDIUM | — | 0 |
| CVE-2025-53392 In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this... | 5.0 | MEDIUM | — | 0 |
| CVE-2025-46014 Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, le... | 8.8 | HIGH | — | 0 |
| CVE-2025-45143 string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input. | 7.0 | HIGH | — | 0 |
| CVE-2025-49493 Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. | 5.8 | MEDIUM | — | 0 |
| CVE-2025-2141 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. ... | 6.1 | MEDIUM | — | 0 |
| CVE-2025-36056 IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. ... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-34052 Rejected reason: An unauthenticated endpoint that exposes firmware version, MAC address, and supported codecs is not indicative of a security boundary being crossed, as this metadata is not inherently... | N/A | NONE | — | 0 |
| CVE-2025-48379 Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format ... | 7.1 | HIGH | — | 0 |
| CVE-2025-36630 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. | 8.4 | HIGH | — | 0 |
| CVE-2025-5692 The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all ve... | 6.3 | MEDIUM | — | 0 |
| CVE-2025-53492 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects M... | 3.7 | LOW | — | 0 |
| CVE-2025-40721 Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by s... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-53493 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects M... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-53494 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affe... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-6943 Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables. | 3.8 | LOW | — | 0 |
| CVE-2025-45424 Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication. | 5.3 | MEDIUM | — | 0 |
| CVE-2025-45814 Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-45813 ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-27042 Memory corruption while processing video packets received from video firmware. | 7.8 | HIGH | — | 0 |
| CVE-2025-52559 Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This ... | 6.8 | MEDIUM | — | 0 |
| CVE-2025-45938 Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter. | 5.4 | MEDIUM | — | 0 |
| CVE-2025-53490 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS)... | 5.6 | MEDIUM | — | 0 |
| CVE-2025-48939 tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying th... | 4.2 | MEDIUM | — | 0 |
| CVE-2025-53489 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).... | 5.6 | MEDIUM | — | 0 |
| CVE-2025-7060 A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation/mkdbajax.php of the component Installer.... | 4.1 | MEDIUM | — | 0 |
| CVE-2025-53500 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affec... | 5.6 | MEDIUM | — | 0 |
| CVE-2025-53501 Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - ... | 8.8 | HIGH | — | 0 |
| CVE-2025-34087 An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allo... | 8.8 | HIGH | — | 0 |
| CVE-2025-7053 A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/em... | 3.5 | LOW | — | 0 |
| CVE-2025-53599 Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-53600 Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment. | 7.5 | HIGH | — | 0 |
| CVE-2025-7070 A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Pairing Request Handler... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-7074 A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulatio... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-7075 A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component... | 6.3 | MEDIUM | — | 0 |
| CVE-2025-7076 A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configur... | 5.4 | MEDIUM | — | 0 |
| CVE-2025-7079 A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the file bluebell_backend/pkg/jwt/jwt.go of the ... | 3.7 | LOW | — | 0 |
| CVE-2025-7107 A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of t... | 5.3 | MEDIUM | — | 0 |
| CVE-2025-6711 An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 ve... | 4.4 | MEDIUM | — | 0 |
| CVE-2025-6712 MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to inefficiencies in memory management related to internal op... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-6713 An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may l... | 7.7 | HIGH | — | 0 |
| CVE-2025-6714 MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue a... | 7.5 | HIGH | — | 0 |
| CVE-2025-45479 Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-53374 Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profi... | 4.3 | MEDIUM | — | 0 |
| CVE-2025-53375 Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated attacker can read any file that the Traefik proces... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-53376 Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated, low-privileged user can run arbitrary OS commands... | 8.8 | HIGH | — | 0 |
| CVE-2025-7259 An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This issue can only be triggered by authorized users and... | 6.5 | MEDIUM | — | 0 |
| CVE-2025-6044 An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to bypass the lock screen and acce... | 6.1 | MEDIUM | — | 0 |
| CVE-2025-40711 SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the id_concesion para... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.