Latest CVE Feed
- 
                                
                                7.8HIGHCVE-2025-23355NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and ... Read more - Published: Oct. 01, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                8.8HIGHCVE-2025-54286Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication.... Read more - Published: Oct. 02, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                7.1HIGHCVE-2025-54287Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via specially crafted snapshot pattern templates using the Pongo2 t... Read more - Published: Oct. 02, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
- 
                                
                                5.3MEDIUMCVE-2025-35054Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can ac... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cryptography
 
- 
                                
                                8.8HIGHCVE-2025-35055Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell or other content executable by the w... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                5.3MEDIUMCVE-2025-35056Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                9.8CRITICALCVE-2025-60772Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate privileges and lock out the legitimate administrator via crafted HTTP requests.... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                5.4MEDIUMCVE-2025-60506Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) can inject arbitrary JavaScript payloads into a comment. When any other user (St... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.5MEDIUMCVE-2025-60427LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the Web UI and direct API calls. The backend does not verify role-based permissions for analytics endpoints, ... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authorization
 
- 
                                
                                6.0MEDIUMCVE-2025-35057Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                4.8MEDIUMCVE-2025-61999OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content is executed in the context of other users when they view affected pages. Successful exploitati... Read more Affected Products : foiaxpress- Published: Oct. 08, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.8MEDIUMCVE-2025-61997OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual R... Read more Affected Products : foiaxpress- Published: Oct. 08, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.8MEDIUMCVE-2025-61996OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Template. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitati... Read more Affected Products : foiaxpress- Published: Oct. 08, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.8MEDIUMCVE-2025-61998OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. Injected content is executed in the context of other users when they click the malicious link. ... Read more Affected Products : foiaxpress- Published: Oct. 08, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.9MEDIUMCVE-2025-62598WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. T... Read more Affected Products : wegia- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                5.5MEDIUMCVE-2025-58277Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.... Read more Affected Products : harmonyos- Published: Oct. 11, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authorization
 
- 
                                
                                5.1MEDIUMCVE-2025-56802The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-202... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cryptography
 
- 
                                
                                5.1MEDIUMCVE-2025-56801The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration dat... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cryptography
 
- 
                                
                                5.1MEDIUMCVE-2025-56800Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password i... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                6.5MEDIUMCVE-2025-56799Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user wer... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
 
                         
                         
                         
                                             
                                            