6.5
CVE-2025-45157 -
Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.
6.5
CVE-2025-52163 -
A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.
4
CVE-2025-54310 -
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
4.8
CVE-2025-50583 -
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
6.5
CVE-2025-46000 -
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.
5.3
CVE-2025-45156 -
Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.
7.5
CVE-2025-50708 -
An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL
6.5
CVE-2025-50586 -
StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
6.5
CVE-2025-7784 - Org.keycloak/keycloak-services: privilege escalation in keycloak admin console (fgapv2 enabled)
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorizeβ¦
8.7
CVE-2025-6185 - Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.