8.6
CVE-2025-64729 - AVEVA Process Optimization Missing Authorization
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.
9.3
CVE-2025-65118 - AVEVA Process Optimization Uncontrolled Search Path Element
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.
9.3
CVE-2025-61943 - AVEVA Process Optimization SQL Injection
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.
9.3
CVE-2025-64691 - AVEVA Process Optimization Code Injection
The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.
10
CVE-2025-61937 - AVEVA Process Optimization Code Injection
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of βtaoimrβ service, potentially resulting in complete compromise of theΒ model application server.
7.2
CVE-2025-31510 -
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
7.5
CVE-2025-68924 -
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
7.8
CVE-2025-68921 -
SteelSeries Nahimic 3 1.10.7 allows Directory traversal.
8.1
CVE-2025-62291 - strongswan: strongSwan: Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 mesβ¦
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
7.5
CVE-2025-71020 -
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.