9.3
CVE-2025-6893 -
An Execution with Unnecessary Privileges vulnerability has been identified in Moxaβs network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to callβ¦
8.7
CVE-2025-6892 -
An Incorrect Authorization vulnerability has been identified in Moxaβs network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploiteβ¦
5.8
CVE-2025-62642 -
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing a remote unauthenticated attacker to create a user account.
6.5
CVE-2025-57164 -
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
9.9
CVE-2025-62645 -
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
3.3
CVE-2025-60361 -
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
3.4
CVE-2025-62643 -
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
6.5
CVE-2025-60514 -
Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.
5.5
CVE-2025-60359 -
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
6.4
CVE-2025-62648 -
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.