Latest CVE Feed
-
0.0
NACVE-2025-52050
In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injectin... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-52049
In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the time... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: Sep. 24, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-9232
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: ... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Denial of Service
-
0.0
NACVE-2025-9231
Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM pl... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Cryptography
-
0.0
NACVE-2025-9230
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an applic... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-41244
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may e... Read more
- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-40838
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-40837
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-40836
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-27262
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-27261
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
0.0
NA- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
-
0.0
NA- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
-
0.0
NACVE-2025-10859
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Information Disclosure
-
6.0
MEDIUMCVE-2025-10217
A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-58767
REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or l... Read more
Affected Products : rexml- Published: Sep. 17, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Denial of Service
-
10.0
CRITICALCVE-2025-34217
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and a sudoers rule granting the printerlogic_ssh grou... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-9993
The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inc... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-9991
The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .... Read more
Affected Products :- Published: Sep. 30, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Path Traversal