Latest CVE Feed
- 
                                
                                
4.8
MEDIUMCVE-2025-11437
A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been publish... Read more
Affected Products : opnform- Published: Oct. 08, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-61999
OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content is executed in the context of other users when they view affected pages. Successful exploitati... Read more
Affected Products : foiaxpress- Published: Oct. 08, 2025
 - Modified: Oct. 22, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-62238
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows r... Read more
- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-54859
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.... Read more
Affected Products :- Published: Oct. 16, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-9980
QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin us... Read more
Affected Products : quick.cms- Published: Oct. 23, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-1679
Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s... Read more
- Published: Oct. 23, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-62244
Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92, and 7.3 GA through update 36 allows re... Read more
- Published: Oct. 13, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-11167
The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.5.6. This is due to insufficient validation on the redirect url supplied ... Read more
Affected Products :- Published: Oct. 11, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-43420
A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-58719
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_11_23h2 windows_server_23h2 +3 more products- Published: Oct. 14, 2025
 - Modified: Oct. 14, 2025
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-48464
Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.... Read more
Affected Products :- Published: Oct. 08, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-10282
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-62981
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8.... Read more
Affected Products :- Published: Oct. 27, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-59448
Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to co... Read more
Affected Products :- Published: Oct. 06, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-20740
In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: ... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Race Condition
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-61776
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may send credentials meant for a private NuGet repository to `api.nuget.org` vi... Read more
Affected Products : dependency-track- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Supply Chain
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-10281
BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-0609
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS).This issue affects Logo Cloud: before 1.18.... Read more
Affected Products :- Published: Oct. 06, 2025
 - Modified: Oct. 06, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.6
MEDIUMCVE-2025-54941
An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or th... Read more
Affected Products : airflow- Published: Oct. 30, 2025
 - Modified: Oct. 30, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.6
MEDIUMCVE-2025-62276
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported vers... Read more
- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Misconfiguration