Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2025-7449

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with specific permissions to cause a denial of service condition through... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Denial of Service
  • 4.3

    MEDIUM
    CVE-2025-6195

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration cond... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Information Disclosure
  • 0.0

    NA
    CVE-2025-65670

    An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak oc... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-65278

    An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Information Disclosure
  • 0.0

    NA
    CVE-2025-65276

    An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_i... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authentication
  • 0.0

    NA
    CVE-2025-50433

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authentication
  • 2.0

    LOW
    CVE-2025-13611

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific c... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Information Disclosure
  • 6.5

    MEDIUM
    CVE-2025-12653

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific conditions could have allowed an unauthenticated user to join arbitrary organizations by changing... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2025-12571

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an unauthenticated user to cause a Denial of Service condition by sending specifically craft... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Denial of Service
  • 6.9

    MEDIUM
    CVE-2025-66028

    OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMa... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2025-65966

    OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been patched in vers... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authentication
  • 0.0

    NA
    CVE-2025-65681

    An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Information Disclosure
  • 0.0

    NA
    CVE-2025-65676

    Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Cross-Site Scripting
  • 0.0

    NA
    CVE-2025-65675

    Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Cross-Site Scripting
  • 0.0

    NA
    CVE-2025-65672

    Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-65669

    An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Authorization
  • 0.0

    NA
    CVE-2025-26155

    NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Misconfiguration
  • 6.5

    MEDIUM
    CVE-2021-4472

    The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2025-64130

    Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.6

    HIGH
    CVE-2025-64129

    Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device.... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 26, 2025
    • Vuln Type: Memory Corruption
Showing 20 of 3493 Results