Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2025-58436

    OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it bec... Read more

    Affected Products : cups
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Denial of Service
  • 6.3

    MEDIUM
    CVE-2025-53939

    Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0.... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authorization
  • 6.5

    MEDIUM
    CVE-2025-53900

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. Thi... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authorization
  • 7.2

    HIGH
    CVE-2025-53899

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges o... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authorization
  • 6.8

    MEDIUM
    CVE-2025-53897

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted ... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Information Disclosure
  • 7.1

    HIGH
    CVE-2025-53896

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched i... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authentication
  • 6.9

    MEDIUM
    CVE-2025-66219

    willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execut... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-66201

    LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing specially crafted OpenAPI specs to its "Actions" feature and making the LLM use those actions. It ... Read more

    Affected Products : librechat
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Server-Side Request Forgery
  • 6.1

    MEDIUM
    CVE-2025-66036

    Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input handling component. This issue has been patched in version 2.4.7.... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.3

    MEDIUM
    CVE-2025-66034

    fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a m... Read more

    Affected Products : fonttools
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Misconfiguration
  • 7.1

    HIGH
    CVE-2025-66027

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, ... Read more

    Affected Products : rallly
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Information Disclosure
  • 6.5

    MEDIUM
    CVE-2025-65113

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows any unauthenticated user to flag any content (users, videos, photos, collections) on the platfo... Read more

    Affected Products : clipbucket
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authorization
  • 9.4

    CRITICAL
    CVE-2025-65112

    PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing,... Read more

    Affected Products :
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Authentication
  • 4.0

    MEDIUM
    CVE-2025-64715

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not... Read more

    Affected Products : cilium
    • Published: Nov. 29, 2025
    • Modified: Nov. 29, 2025
    • Vuln Type: Misconfiguration
  • 6.8

    MEDIUM
    CVE-2025-58309

    Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.... Read more

    Affected Products : harmonyos
    • Published: Nov. 28, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Authorization
  • 9.9

    CRITICAL
    CVE-2025-12421

    Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform acco... Read more

    Affected Products : mattermost_server
    • Published: Nov. 27, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Authentication
  • 9.9

    CRITICAL
    CVE-2025-12419

    Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take ... Read more

    Affected Products : mattermost_server
    • Published: Nov. 27, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Authentication
  • 9.3

    CRITICAL
    CVE-2025-66259

    Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php use... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Injection
  • 8.4

    HIGH
    CVE-2025-58302

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more

    Affected Products : emui harmonyos
    • Published: Nov. 28, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Authorization
  • 9.9

    CRITICAL
    CVE-2025-66255

    Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation all... Read more

    Affected Products :
    • Published: Nov. 26, 2025
    • Modified: Nov. 28, 2025
    • Vuln Type: Authentication
Showing 20 of 3034 Results