Latest CVE Feed
- 
                                
                                8.8HIGHCVE-2025-10639The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker with network access to this port can use weak hardcoded credentials to login to the FTP server and modify or ... Read more Affected Products :- Published: Oct. 21, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                8.4HIGHCVE-2025-59489Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unit... Read more - Published: Oct. 03, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                8.1HIGHCVE-2025-61784LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the server to make arbitrary HTTP requests to internal and exter... Read more Affected Products : llama-factory- Published: Oct. 07, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                4.8MEDIUMCVE-2025-4614An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leak... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                7.2HIGHCVE-2025-4615An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
- 
                                
                                6.9MEDIUMCVE-2025-62414Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject malicious Jav... Read more Affected Products : bagisto- Published: Oct. 16, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.9MEDIUMCVE-2025-62415Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the malic... Read more Affected Products : bagisto- Published: Oct. 16, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.4MEDIUMCVE-2025-61765python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserializ... Read more Affected Products :- Published: Oct. 06, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
- 
                                
                                6.8MEDIUMCVE-2025-62416Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows... Read more Affected Products : bagisto- Published: Oct. 16, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
- 
                                
                                7.8HIGHCVE-2025-62417Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet wil... Read more Affected Products : bagisto- Published: Oct. 16, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Injection
 
- 
                                
                                6.9MEDIUMCVE-2025-62418Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malici... Read more Affected Products : bagisto- Published: Oct. 16, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.1MEDIUMCVE-2025-60781PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_name parameter.... Read more Affected Products : php_education_management- Published: Oct. 20, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                9.8CRITICALCVE-2025-35062Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                8.2HIGHCVE-2025-35058Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX s... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                8.2HIGHCVE-2025-35061Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Authentication
 
- 
                                
                                6.1MEDIUMCVE-2025-35059Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                6.1MEDIUMCVE-2025-47890An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions;... Read more - Published: Oct. 14, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                5.5MEDIUMCVE-2025-35060Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.... Read more - Published: Oct. 09, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                7.8HIGHCVE-2025-46774An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related execu... Read more Affected Products : forticlient- Published: Oct. 14, 2025
- Modified: Oct. 22, 2025
- Vuln Type: Cryptography
 
- 
                                
                                7.0HIGHCVE-2025-59289Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 22, 2025
 
 
                         
                         
                         
                                             
                                            