Latest CVE Feed
-
7.7
HIGHCVE-2025-57809
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. This issue has been resolved in version 0.1.21.... Read more
Affected Products : xgrammar- Published: Aug. 25, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-52217
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.... Read more
Affected Products : selectzero- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICAL- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-52218
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text or limited HTML into the login page.... Read more
Affected Products : selectzero- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-52219
SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML Injection.... Read more
Affected Products : selectzero- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-56432
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component... Read more
Affected Products : nagios_xi- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-57810
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage ... Read more
Affected Products : jspdf- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-50974
The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated remote attacker can inject arbitrary OS commands ... Read more
Affected Products : ipfire- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-52184
Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.... Read more
Affected Products : helpy- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-50976
IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.... Read more
Affected Products : ipfire- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-50975
IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing an authenticated administrator to inject persisten... Read more
Affected Products : ipfire- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-52353
An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its... Read more
Affected Products : badaso- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-55443
Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these log... Read more
Affected Products : telpo_mdm- Published: Aug. 26, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Information Disclosure
-
5.8
MEDIUMCVE-2025-56694
Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protected photo albums.... Read more
Affected Products : fotoshare_cloud- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-55730
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution ... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
5.6
MEDIUMCVE-2025-50985
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML r... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.6
MEDIUMCVE-2025-50986
diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE,... Read more
Affected Products : diskover- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-50989
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowi... Read more
Affected Products : opnsense- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-52122
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).... Read more
Affected Products : freeform- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-50978
In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are handled. By injecting a specially crafted path payload an attacker can cause arbitrary JavaScript to execute when a victim views the manipu... Read more
Affected Products : gitblit- Published: Aug. 27, 2025
- Modified: Sep. 09, 2025
- Vuln Type: Cross-Site Scripting