0.0
CVE-2025-49816 -
Not used
0.0
CVE-2025-49814 -
Not used
8.1
CVE-2025-4922 - Nomad Vulnerable To Incorrect ACL Policy Lookup Attached To A Job
Nomad Community and Nomad Enterprise (βNomadβ) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
9.3
CVE-2025-32711 - M365 Copilot Information Disclosure Vulnerability
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
5.5
CVE-2025-35941 - mySCADA PRO Manager Password Disclosure
A password is exposed locally.
6.4
CVE-2025-5144 - The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βdata-date-*β parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leβ¦
9.8
CVE-2025-49710 - Integer overflow in OrderedHashTable
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
9.8
CVE-2025-49709 - Memory corruption in canvas surfaces
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
7.8
CVE-2025-5687 - Local privilege escalation vulnerability in Mozilla VPN clients for macOS v2.27.0 and below.
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.*. This vulnerability was fixed in Mozilla VPN 2.28.0 (macOS).
7.2
CVE-2025-3302 - Xagio SEO <= 7.1.0.16 - Unauthenticated Stored Cross-Site Scripting via 'HTTP_REFERER'
The Xagio SEO β AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βHTTP_REFERERβ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injectβ¦