4.6
CVE-2025-64174 - OpenMage is vulnerable to XSS in Admin Notifications
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scrip…
5.4
CVE-2025-33110 - IBM OpenPages Vulnerable to HTML Injection
IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
7.5
CVE-2025-64173 - Apollo Router Core: Access Control Bypass on Polymorphic Types
Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access contr…
8.8
CVE-2025-12486 - Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability
Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Minimal user interaction is required to exploit this vulnerability. The specific fl…
9.8
CVE-2025-12487 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…
9.8
CVE-2025-12488 - oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Executio…
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulne…
7.8
CVE-2025-12489 - evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability
evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server. An attacker must first obtain the ability to execute low-privileged code on the target system in o…
8.8
CVE-2025-12490 - Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability
Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata …
8.8
CVE-2022-50590 - SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the…
9.3
CVE-2022-50589 - SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.