Latest CVE Feed
-
9.8
CRITICALCVE-2025-62354
Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code execution.... Read more
Affected Products : cursor- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-56396
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Authorization
-
0.0
NACVE-2025-50402
FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-50399
FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-46174
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Authorization
-
0.0
NACVE-2025-45311
Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-13601
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the ... Read more
Affected Products : glib- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-9191
The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level acc... Read more
Affected Products : houzez- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-9163
The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property... Read more
Affected Products : houzez- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-13674
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service... Read more
Affected Products : wireshark- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Denial of Service
-
0.0
NACVE-2025-62728
SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift A... Read more
Affected Products : hive- Published: Nov. 26, 2025
- Modified: Nov. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-59390
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a cryp... Read more
Affected Products : druid- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Authentication
-
7.4
HIGHCVE-2025-13735
Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is associated with program files Code/nr_fw/DLP/src/NrCgi.C. This issue affects Lapwing_Linux: before 2025/11/26.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-9558
There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received data is copied into the link.rx.buf receiver buffer without any validation on the data size.... Read more
Affected Products : zephyr- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-9557
An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, this can still lead to a crash and a resultant denial of service.... Read more
Affected Products : zephyr- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2025-59820
In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex/tga/kis_tga_import.cpp (aka KisTgaImport). Control flow proceeds even when a number of pixels becomes negative.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Memory Corruption
-
3.2
LOWCVE-2025-55174
In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-12061
The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-64983
Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain access to the device.... Read more
Affected Products :- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-66026
REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the Mediapool view where the request parameter args[types] is rendered into an info banner without HTML-escaping. This allows arbitrary Java... Read more
Affected Products : redaxo- Published: Nov. 26, 2025
- Modified: Nov. 26, 2025
- Vuln Type: Cross-Site Scripting