Latest CVE Feed
-
7.2
HIGHCVE-2025-60787
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve... Read more
Affected Products : motioneye- Published: Oct. 03, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-60445
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the dayrui/Fcms/Library/Upload.php component, allowing attackers to inject mal... Read more
Affected Products : xunruicms- Published: Oct. 03, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-62185
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.... Read more
Affected Products : anki- Published: Oct. 07, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-62186
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.... Read more
Affected Products : anki- Published: Oct. 07, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Misconfiguration
-
3.3
LOWCVE-2025-62187
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).... Read more
Affected Products : anki- Published: Oct. 07, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2025-60298
Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parame... Read more
Affected Products : novel-plus- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-60299
Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comm... Read more
Affected Products : novel-plus- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-60314
Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execu... Read more
Affected Products : simple_web_inventory_system- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-60828
WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.... Read more
- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-60830
redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.... Read more
Affected Products : redragon-erp- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-60833
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.... Read more
Affected Products : uzy-ssm-mall- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: XML External Entity
-
6.5
MEDIUMCVE-2025-60834
A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.... Read more
Affected Products : uzy-ssm-mall- Published: Oct. 08, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Injection
-
0.0
NACVE-2023-53642
In the Linux kernel, the following vulnerability has been resolved: x86: fix clear_user_rep_good() exception handling annotation This code no longer exists in mainline, because it was removed in commit d2c95f9d6802 ("x86: don't use REP_GOOD or ERMS for ... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2023-53469
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix null-ptr-deref in unix_stream_sendpage(). Bing-Jhong Billy Jheng reported null-ptr-deref in unix_stream_sendpage() with detailed analysis and a nice repro. unix_stream_sen... Read more
Affected Products : linux_kernel- Published: Oct. 01, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Race Condition
-
6.1
MEDIUMCVE-2025-60312
Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Conver... Read more
Affected Products : markdown_to_html_converter- Published: Oct. 07, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2025-60969
Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.... Read more
- Published: Oct. 06, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Path Traversal
-
7.3
HIGHCVE-2025-60967
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.... Read more
- Published: Oct. 06, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-60965
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and pos... Read more
- Published: Oct. 06, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-60964
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and pos... Read more
- Published: Oct. 06, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-52658
HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.... Read more
Affected Products : dryice_myxalytics- Published: Oct. 03, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Supply Chain