8.1
CVE-2025-6505 -
Unauthorized access and impersonation can occur in versionsย 4.6.2.3226ย and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access. ย Whenโฆ
8.4
CVE-2025-6504 - Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.ย Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could โฆ
6.9
CVE-2025-54422 - Sandboxie exposes encrypted sandbox key during password change
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, expoโฆ
6.9
CVE-2025-7458 - SQLite integer overflow in key info allocation may lead to information disclosure.
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a laโฆ
5.4
CVE-2025-6060 - XSS in DECE Software's Geodi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before GEODI Setup 9.0.146.
4.4
CVE-2025-41241 - Denial-of-service vulnerability
VMware vCenter contains a denial-of-service vulnerability.ย A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
7.2
CVE-2025-6175 - CRLF Injection in DECE Software's Geodi
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting.This issue affects Geodi: before GEODI Setup 9.0.146.
4.8
CVE-2025-40686 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'employeeid' parameter in/detailview.php.
4.8
CVE-2025-40685 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searcstate' parameter in/state.php.
4.8
CVE-2025-40684 - Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System
Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through theย 'searccountry' parameter in/country.php.