Latest CVE Feed
- 
                                
                                
9.9
CRITICALCVE-2025-62650
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.... Read more
Affected Products : restaurant_brands_international_assistant- Published: Oct. 17, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
7.7
HIGHCVE-2025-62646
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.... Read more
Affected Products : restaurant_brands_international_assistant- Published: Oct. 17, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
8.6
HIGHCVE-2025-62643
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.... Read more
Affected Products : restaurant_brands_international_assistant- Published: Oct. 17, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cryptography
 
 - 
                                
                                
7.7
HIGHCVE-2025-62644
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.... Read more
Affected Products : restaurant_brands_international_assistant- Published: Oct. 17, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-11618
A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects applications usi... Read more
Affected Products : freertos-plus-tcp- Published: Oct. 10, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.4
MEDIUMCVE-2025-11616
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using ... Read more
Affected Products : freertos-plus-tcp- Published: Oct. 10, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
5.4
MEDIUMCVE-2025-11617
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommen... Read more
Affected Products : freertos-plus-tcp- Published: Oct. 10, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
1.8
LOWCVE-2025-6075
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-64362
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Elements k-elements allows DOM-Based XSS.This issue affects K Elements: from n/a through < 5.5.0.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-64361
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: from n/a t... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.5
HIGHCVE-2025-64360
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
7.5
HIGHCVE-2025-64359
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64358
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from n/a through <= 2... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64357
Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <= 3.1.6.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64356
Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from n/a through <= 1.4.3.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-64354
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
3.8
LOWCVE-2025-64350
Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.1
MEDIUMCVE-2025-62264
Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
5.8
MEDIUMCVE-2025-62649
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.... Read more
Affected Products : restaurant_brands_international_assistant- Published: Oct. 17, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11629
A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclos... Read more
Affected Products : docsys- Published: Oct. 12, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Injection