5.3
CVE-2025-13820 - Comments โ wpDiscuz < 7.6.40 - Unauthenticated Account Takeover
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
5.3
CVE-2025-69413 - Gitea: Gitea: Information disclosure via differing authentication responses
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
8.1
CVE-2025-12805 - Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user iโฆ
3.4
CVE-2025-69412 -
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
6.1
CVE-2025-67711 - Reflected XSS vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโs browser.
6.1
CVE-2025-67710 - Stored XSS vulnerability in ArcGIS Server
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโs browser.
6.1
CVE-2025-67709 - There is a cross site scripting issue in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโs browser.
6.1
CVE-2025-67708 - Reflected cross-site scripting (XSS) vulnerability in ArcGIS Server.
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victimโs browser.
5.6
CVE-2025-67707 - Unvalidated File Upload vulnerability in ArcGIS Server.
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the serverโs designated upload directories. However, the serverโs architecture enforces controls that restrict uploaded โฆ
5.6
CVE-2025-67706 - Unvalidated File Upload vulnerability in ArcGIS Server.
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the serverโs designated upload directories. However, the serverโs architecture enforces controls that restrict uploaded โฆ