Latest CVE Feed
- 
                                
                                
6.1
MEDIUMCVE-2025-59982
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the dashboard search field that, when visited by another user, enables the at... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
9.6
CRITICALCVE-2025-10284
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
9.3
CRITICALCVE-2025-59974
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context o... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.7
MEDIUMCVE-2025-37727
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex... Read more
- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.8
CRITICALCVE-2025-35050
Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by New... Read more
- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-60002
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-59994
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Quick Template page that, when visited by another user, enables the attac... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-59990
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the at... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-59996
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Configuration View page that, when visited by another user, enables the a... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
8.2
HIGHCVE-2025-52960
A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). W... Read more
Affected Products : junos- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
6.9
MEDIUMCVE-2025-59958
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to cause impact to confidentiality and availab... Read more
Affected Products : junos_os_evolved- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
7.1
HIGHCVE-2025-59976
An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to access any file on the file system. Using specially crafted GET methods, an attacker ... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-62240
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through upd... Read more
- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
8.5
HIGHCVE-2025-11198
A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with malicious ones. If a trusted user initiates depl... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
5.1
MEDIUMCVE-2025-41088
Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Ele... Read more
Affected Products :- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-10124
The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. When a page containing the shortcode is visited, the bookings are deleted.... Read more
Affected Products : booking_manager- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-11570
Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if the code is executed outside of Drupal; the function i... Read more
Affected Products :- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-59984
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to exe... Read more
Affected Products : junos_space- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.7
MEDIUMCVE-2025-10282
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-11449
ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially cr... Read more
Affected Products :- Published: Oct. 10, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Cross-Site Scripting