Latest CVE Feed
-
6.5
MEDIUMCVE-2025-63291
When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the sp... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-13177
A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit is now public and may be used. The vendor was... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.1
MEDIUMCVE-2025-13180
A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. Impacted is an unknown function of the file /edit_profile. Performing manipulation of the argument first_name/last_name results in b... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Scripting
-
1.1
LOWCVE-2025-4616
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-13238
A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may... Read more
Affected Products :- Published: Nov. 16, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-12182
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user h... Read more
Affected Products : qi_blocks- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-9317
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.... Read more
Affected Products : aveva_edge- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-12849
The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated us... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-8386
The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in hor... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-64308
The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
8.7
HIGHCVE-2021-4469
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote at... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-13178
A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile Handler. This manipulation of the argument first_name/last_name causes basic cross site scr... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-63725
Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.8
MEDIUMCVE-2025-13198
A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possi... Read more
Affected Products : douphp- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-13187
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of credentials. The at... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-64307
The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, c... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-55034
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-13165
EasyFlow GP developed by Digiwin has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that result in denial of web service.... Read more
Affected Products :- Published: Nov. 17, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-13266
A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/cn/wwwlike/sys/api/SysFileApi.java of the component VLifeApi. Such manipulation of the argument fileName l... Read more
Affected Products :- Published: Nov. 17, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-13265
A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traver... Read more
Affected Products :- Published: Nov. 17, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Path Traversal