Latest CVE Feed
-
9.8
CRITICALCVE-2025-13451
A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. T... Read more
Affected Products : online_shop_project- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-13468
A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executi... Read more
Affected Products : alumni_management_system- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-41074
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system ... Read more
Affected Products : limesurvey- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-41075
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is... Read more
Affected Products : limesurvey- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-41076
In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Y... Read more
Affected Products : limesurvey- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-36153
IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : concert- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-36158
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.... Read more
Affected Products : concert- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Path Traversal
-
6.2
MEDIUMCVE-2025-36159
IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.... Read more
Affected Products : concert- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-36160
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.... Read more
Affected Products : concert- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-59245
Microsoft SharePoint Online Elevation of Privilege Vulnerability... Read more
Affected Products : sharepoint_online- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
-
10.0
CRITICALCVE-2025-49752
Azure Bastion Elevation of Privilege Vulnerability... Read more
Affected Products : azure_bastion_developer- Published: Nov. 20, 2025
- Modified: Nov. 21, 2025
-
5.4
MEDIUMCVE-2025-66067
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows DOM-Based XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.13.1.2.... Read more
Affected Products : funnel_builder- Published: Nov. 21, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-66064
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.... Read more
Affected Products : rafflepress- Published: Nov. 21, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-41735
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.... Read more
Affected Products : ewio2-m_firmware ewio2-m ewio2-m-bm_firmware ewio2-m-bm ewio2-bm_firmware ewio2-bm- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-41737
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.... Read more
Affected Products : ewio2-m_firmware ewio2-m ewio2-m-bm_firmware ewio2-m-bm ewio2-bm_firmware ewio2-bm- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-41736
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.... Read more
Affected Products : ewio2-m_firmware ewio2-m ewio2-m-bm_firmware ewio2-m-bm ewio2-bm_firmware ewio2-bm- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-41734
An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.... Read more
Affected Products : ewio2-m_firmware ewio2-m ewio2-m-bm_firmware ewio2-m-bm ewio2-bm_firmware ewio2-bm- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-41733
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.... Read more
Affected Products : ewio2-m_firmware ewio2-m ewio2-m-bm_firmware ewio2-m-bm ewio2-bm_firmware ewio2-bm- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-58034
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 throug... Read more
Affected Products : fortiweb- Actively Exploited
- Published: Nov. 18, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-66112
Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Toolkit by WebYes: from n/a through <= 2.0.4.... Read more
Affected Products :- Published: Nov. 21, 2025
- Modified: Nov. 21, 2025
- Vuln Type: Authorization