Latest CVE Feed
-
8.7
CVSS31CVE-2025-4985
A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4983
A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-1763
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before ... Read more
Affected Products : gitlab- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4992
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser ses... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4986
A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4991
A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4989
A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4984
A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4990
A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4988
A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's bro... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-0602
A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.6
CVSS31CVE-2025-41235
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.3
CVSS31CVE-2025-48881
Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management configuration exists can be listed, viewed, edited, created... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.2
CVSS31CVE-2025-31189
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: May. 29, 2025
- Modified: May. 30, 2025
-
8.1
CVSS31CVE-2025-48936
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to c... Read more
Affected Products : zitadel- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.8
CVSS31CVE-2025-2501
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.8
CVSS31CVE-2025-5307
Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue to potentially disclose information and to execute arbitrary code on affected installations of Sante DICOM Viewer Pro.... Read more
Affected Products : dicom_viewer_pro- Published: May. 29, 2025
- Modified: May. 30, 2025
-
7.8
CVSS31CVE-2025-2502
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.8
CVSS31CVE-2025-4636
Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains control of the this user would be able to privilege escalate to the root user... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.8
CVSS31CVE-2025-44906
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025