Common Vulnerabilities and Exposures (CVE)

CVE-2025-62276

Oct 31, 2025 23:34:20 UTC

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older u...

CVE-2014-2381

Oct 31, 2025 23:19:54 UTC

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.

CVE-2014-5399

Oct 31, 2025 23:17:37 UTC

SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-5398

Oct 31, 2025 23:16:04 UTC

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, r...

CVE-2014-5397

Oct 31, 2025 23:14:04 UTC

Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2380

Oct 31, 2025 23:11:04 UTC

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

CVE-2014-2349

Oct 31, 2025 22:56:34 UTC

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet prog...

CVE-2014-2350

Oct 31, 2025 22:55:07 UTC

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet prog...

CVE-2025-12464

Oct 31, 2025 21:15:48 UTC

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still bei...

CVE-2025-60711

Oct 31, 2025 20:28:48 UTC

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2025-59501

Oct 31, 2025 20:28:48 UTC

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

CVE-2025-59500

Oct 31, 2025 20:28:47 UTC

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

CVE-2025-59503

Oct 31, 2025 20:28:47 UTC

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59273

Oct 31, 2025 20:28:46 UTC

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59286

Oct 31, 2025 20:28:45 UTC

Copilot Spoofing Vulnerability