Latest CVE Feed
-
0.0
NACVE-2025-56392
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2025-36262
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-36132
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2024-55017
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unauthorized access to victim accounts.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-56132
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the exi... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-43827
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-11149
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-11148
All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally, or via CI, to confirm no conflicts exist in git branches. However, the library follows these conventions... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-57254
An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the username and password POST parameters. The application fails to properly s... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-57197
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN ve... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-56764
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2025-56675
The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
0.0
NACVE-2025-56513
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary execut... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Supply Chain
-
0.0
NACVE-2025-56200
A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol ... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-54477
Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.... Read more
Affected Products : joomla\!- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-51495
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-35027
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, t... Read more
Affected Products :- Published: Sep. 26, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-23293
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
4.6
MEDIUMCVE-2025-23292
NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to partial denial of service (UI component).... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
2.4
LOWCVE-2025-23291
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability may lead to information disclosure.... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization