Recent CVE entries
Stay updated about the Latest Security Vulnerabilities
Showing 27 CVEs published in the last 12 hours.
| CVE ID & CVSS | Description |
|---|---|
|
CVE-2025-9982
6.9 (Medium)
Show References |
A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers with access to the source code or the server file system to retrieve authentication details, potentially leading to privilege escalation.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Published: November 14, 2025; 2:15:47 PM UTC
43 minutes ago
|
|
CVE-2025-12149
6 (Medium)
Show References |
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is trigged from a Signal's watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Published: November 14, 2025; 2:15:46 PM UTC
43 minutes ago
|
|
CVE-2025-11918
7.1 (High)
Show References |
Rockwell Automation Arena® suffers from a
stack-based buffer overflow vulnerability. The specific flaw exists within the
parsing of DOE files. Local attackers are able to exploit this issue to
potentially execute arbitrary code on affected installations of Arena®. Exploiting
the vulnerability requires opening a malicious DOE file.
Published: November 14, 2025; 2:15:45 PM UTC
43 minutes ago
|
|
CVE-2025-10018
4.8 (Medium)
Show References |
QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed on every page. By default admin user is not able to add JavaScript into the website.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Published: November 14, 2025; 2:15:44 PM UTC
43 minutes ago
|
|
CVE-2025-8855
8.1 (High)
Show References |
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information.This issue affects Brokerage Automation: before 1.1.71.
Published: November 14, 2025; 1:15:45 PM UTC
1 hour ago
|
|
CVE-2025-11981
4.9 (Medium)
Show References |
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: November 14, 2025; 12:15:43 PM UTC
2 hours ago
|
|
|
|
CVE-2025-11794
4.9 (Medium)
Show References |
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint
Published: November 14, 2025; 11:15:45 AM UTC
3 hours ago
|
|
CVE-2025-55073
5.4 (Medium)
Show References |
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.
Published: November 14, 2025; 8:15:45 AM UTC
6 hours ago
|
|
CVE-2025-55070
6.5 (Medium)
Show References |
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
Published: November 14, 2025; 8:15:45 AM UTC
6 hours ago
|
|
CVE-2025-41436
3.1 (Low)
Show References |
Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
Published: November 14, 2025; 8:15:45 AM UTC
6 hours ago
|
|
CVE-2025-11776
4.3 (Medium)
Show References |
Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
Published: November 14, 2025; 8:15:43 AM UTC
6 hours ago
|
|
CVE-2025-64444
8.6 (High)
Show References |
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.
Published: November 14, 2025; 6:15:42 AM UTC
8 hours ago
|
|
CVE-2025-10686
N/A (Info)
Show References |
The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.
Published: November 14, 2025; 6:15:42 AM UTC
8 hours ago
|
|
CVE-2025-13161
8.7 (High)
Show References |
IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Published: November 14, 2025; 4:15:54 AM UTC
10 hours ago
|
|
CVE-2025-13160
6.9 (Medium)
Show References |
IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access specific APIs to obtain sensitive information from the internal network.
Published: November 14, 2025; 4:15:54 AM UTC
10 hours ago
|
|
CVE-2025-9479
N/A (Info)
Show References |
Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published: November 14, 2025; 3:15:57 AM UTC
11 hours ago
|
|
CVE-2025-13107
N/A (Info)
Show References |
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: November 14, 2025; 3:15:56 AM UTC
11 hours ago
|
|
CVE-2025-13102
N/A (Info)
Show References |
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: November 14, 2025; 3:15:56 AM UTC
11 hours ago
|
|
CVE-2025-13097
N/A (Info)
Show References |
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: November 14, 2025; 3:15:56 AM UTC
11 hours ago
|
|
CVE-2025-12904
7.2 (High)
Show References |
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: November 14, 2025; 3:15:56 AM UTC
11 hours ago
|
|
CVE-2024-9126
N/A (Info)
Show References |
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-7021
N/A (Info)
Show References |
Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-7017
N/A (Info)
Show References |
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-13983
N/A (Info)
Show References |
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-13178
N/A (Info)
Show References |
Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-11920
N/A (Info)
Show References |
Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published: November 14, 2025; 3:15:55 AM UTC
11 hours ago
|
|
CVE-2024-11919
N/A (Info)
Show References |
Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: November 14, 2025; 3:15:54 AM UTC
11 hours ago
|