7.5
CVE-2025-11678 - Stack-based Buffer Overflow in libwebsockets DNS response parsing
Stack-based Buffer Overflowย in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label lโฆ
6.3
CVE-2025-11677 - Use After Free in libwebsockets WebSocket server
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handlesย LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
5.3
CVE-2025-8349 - Cross-Site Scripting (XSS) stored in Tawk Live Chat
Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed withoโฆ
9.3
CVE-2025-41028 - SQL injection in Epsilon RH
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter โsEstadoUsrโ in โ/epsilonnetws/WSAvisos.asmxโ.
2.9
CVE-2025-57837 -
Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.
0.0
CVE-2025-62680 -
Not used
0.0
CVE-2025-62681 -
Not used
0.0
CVE-2025-62684 -
Not used
0.0
CVE-2025-62682 -
Not used
0.0
CVE-2025-62683 -
Not used