8.8
CVE-2025-64106 - Cursor: Speedbump Modal Bypass in MCP Server Deep-Link
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables specially crafted deep-links to bypass the standard security warnings and conceal executed commands from users if they choose to accept the serveβ¦
8.2
CVE-2025-59595 -
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.
8.7
CVE-2025-62722 - LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the tβ¦
7.1
CVE-2025-62721 - LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, regaβ¦
7.1
CVE-2025-62720 - LinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private Links
LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system, including private links that should only be accessible to their owners. The HTML and CSV export functions in the Expoβ¦
2.3
CVE-2025-62719 - LinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching Functionality
LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination is not an internal or private network resource. Thβ¦
8.4
CVE-2025-54526 - Fuji Electric Monitouch V-SFT-6 Stack-based Buffer Overflow
Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.
5.3
CVE-2025-62715 - ClipBucket v5: Stored XSS via Collection Tags
ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucketβs Collection tags feature. An authenticated normal user can create a tag containing HTML or JavaScript, which is later rendered unescaped in β¦
8.4
CVE-2025-54496 - Fuji Electric Monitouch V-SFT-6 Heap-based Buffer Overflow
A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code.
5.3
CVE-2025-62520 - MantisBT unauthorized disclosure of private project column configuration
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-level checks, any non-admin user with access to manage_config_columns_page.php can use the Copy From action to retrieve the columns configuration from a private project they have β¦