Latest CVE Feed
-
4.7
MEDIUMCVE-2025-26787
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user ... Read more
Affected Products : signserver- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-63662
Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access sensitive information.... Read more
Affected Products : gt_edge_ai- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-63663
Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.... Read more
Affected Products : gt_edge_ai- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-63664
Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.... Read more
Affected Products : gt_edge_ai- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-68668
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this v... Read more
Affected Products : n8n- Published: Dec. 26, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
9.8
CRITICAL- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-65790
A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG contain... Read more
Affected Products : fuguhub- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-65837
PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.... Read more
Affected Products : publiccms- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-68926
RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both... Read more
Affected Products : rustfs- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-58937
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tacticool tacticool allows PHP Local File Inclusion.This issue affects Tacticool: from n/a through <= 1.0.13.... Read more
Affected Products : tacticool- Published: Dec. 18, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-58929
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pantry pantry allows PHP Local File Inclusion.This issue affects Pantry: from n/a through <= 1.4.... Read more
Affected Products : pantry- Published: Dec. 18, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
8.2
HIGHCVE-2025-58894
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Good Mood good-mood allows PHP Local File Inclusion.This issue affects Good Mood: from n/a through <= 1.16.... Read more
Affected Products : good_mood- Published: Dec. 18, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-65203
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated f... Read more
Affected Products : keepassxc-browser- Published: Dec. 17, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2024-46060
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local l... Read more
- Published: Dec. 17, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2024-46062
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a l... Read more
- Published: Dec. 17, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2025-58893
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Alright alright allows PHP Local File Inclusion.This issue affects Alright: from n/a through <= 1.6.1.... Read more
Affected Products : alright- Published: Dec. 18, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-65233
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a cr... Read more
Affected Products : slims- Published: Dec. 17, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-69089
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto Listings auto-listings allows Stored XSS.This issue affects Auto Listings: from n/a through <= 2.7.1.... Read more
Affected Products : auto_listings- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-69088
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offers WooCommerce woo-combo-offers allows DOM-Based XSS.This issue affects Combo Offers WooCommerce: from n/a through <= 4.2.... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-69034
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8.... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal