Common Vulnerabilities and Exposures (CVE)

CVE-2025-64781

Dec 12, 2025 20:26:03 UTC

In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1, "External page display restriction" is set to "Do not limit" in the initial configuration. With this configurat...

CVE-2025-58576

Dec 12, 2025 20:23:14 UTC

Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended...

CVE-2025-61987

Dec 12, 2025 20:22:14 UTC

GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. do not validate origins in WebSockets. If a user accesses a crafted page, Chat information sent to the user may be...

CVE-2024-58314

Dec 12, 2025 20:13:23 UTC

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands thro...

CVE-2024-58304

Dec 12, 2025 20:11:11 UTC

SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through the 'descr...

CVE-2025-54109

Dec 12, 2025 20:07:20 UTC

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

CVE-2025-54113

Dec 12, 2025 20:06:46 UTC

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-54114

Dec 12, 2025 20:06:25 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

CVE-2025-14572

Dec 12, 2025 20:06:23 UTC

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAuthGlobalConfig. Performing manipulation of the argument hidcontact results in memory corruption. Remote exploitation of t...

CVE-2025-49957

Dec 12, 2025 20:06:02 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected ...

CVE-2025-49958

Dec 12, 2025 20:05:13 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocom...

CVE-2025-66430

Dec 12, 2025 20:03:32 UTC

Plesk 18.0 has Incorrect Access Control.

CVE-2025-67734

Dec 12, 2025 20:01:48 UTC

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing ...

CVE-2025-65854

Dec 12, 2025 19:57:56 UTC

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.

CVE-2025-13665

Dec 12, 2025 19:54:41 UTC

The System Console Utility for Windows is vulnerable to a DLL planting vulnerability