6.5
CVE-2025-65113 - ClipBucket v5 Unauthenticated Object Flagging Vulnerability
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows any unauthenticated user to flag any content (users, videos, photos, collections) on the platform. This can lead to mass flagging attacks, β¦
4
CVE-2025-64715 - Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not attached to any network inβ¦
6.1
CVE-2025-65892 -
Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.
6.1
CVE-2025-65540 -
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scriβ¦
6.5
CVE-2025-13683 -
Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.
8.8
CVE-2025-12183 - org.lz4:lz4-java - Out-of-Bounds Memory Access
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
5.9
CVE-2025-11156 - Improper Service Loading Vulnerability in Netskope Endpoint DLP Driver
Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited,Β a local, authenticated user with Administrator privilegesΒ can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blueβ¦
5.3
CVE-2025-59792 - Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
5.4
CVE-2025-59790 - Apache Kvrocks: RESET command grants admin privileges
Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
8
CVE-2025-12638 - Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_fileβ¦
Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses Python's tarfile.extractall() method without the security-critical filter='data' parameter. Although Keras attemβ¦