CVE-2025-30001 - Apache StreamPark: Authenticated users can trigger remote command execution
CVE ID : CVE-2025-30001
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-30001
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-37727 - Elasticsearch Insertion of sensitive information in log file
CVE ID : CVE-2025-37727
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-37727
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41088 - Stored Cross-Site Scripting (XSS) in CMS
CVE ID : CVE-2025-41088
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41088
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-41089 - Reflected Cross-Site Scripting (XSS) in CMS
CVE ID : CVE-2025-41089
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-41089
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52630 - HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability
CVE ID : CVE-2025-52630
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52630
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52632 - HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
CVE ID : CVE-2025-52632
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52632
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52634 - HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed
CVE ID : CVE-2025-52634
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52634
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52650 - HCL AION is susceptible to Inline script execution allowed in CSP vulnerability
CVE ID : CVE-2025-52650
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52650
Published : Oct. 10, 2025, 10:15 a.m. | 43 minutes ago
Description : Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61856 - V-SFT Buffer Overflow Vulnerability
CVE ID : CVE-2025-61856
Published : Oct. 10, 2025, 10:19 a.m. | 39 minutes ago
Description : A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61856
Published : Oct. 10, 2025, 10:19 a.m. | 39 minutes ago
Description : A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52635 - HCL AION is susceptible to Trusted types in scripts not enforced in CSP
CVE ID : CVE-2025-52635
Published : Oct. 10, 2025, 10:21 a.m. | 37 minutes ago
Description : A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52635
Published : Oct. 10, 2025, 10:21 a.m. | 37 minutes ago
Description : A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52624 - HCL AION is susceptible to Bypass of the script allow list configuration vulnerability
CVE ID : CVE-2025-52624
Published : Oct. 10, 2025, 10:25 a.m. | 33 minutes ago
Description : A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52624
Published : Oct. 10, 2025, 10:25 a.m. | 33 minutes ago
Description : A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61858 - An out-of-bounds write vulnerability exists in VS6
CVE ID : CVE-2025-61858
Published : Oct. 10, 2025, 10:28 a.m. | 30 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61858
Published : Oct. 10, 2025, 10:28 a.m. | 30 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-52625 - HCL AION is susceptible to Cacheable SSL Page Found vulnerability
CVE ID : CVE-2025-52625
Published : Oct. 10, 2025, 10:28 a.m. | 29 minutes ago
Description : A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-52625
Published : Oct. 10, 2025, 10:28 a.m. | 29 minutes ago
Description : A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to attackers with access to the device or browser This issue affects AION: 2.0.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61857 - V-SFT Font Parsing Out-of-Bounds Write Vulnerability
CVE ID : CVE-2025-61857
Published : Oct. 10, 2025, 10:29 a.m. | 29 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61857
Published : Oct. 10, 2025, 10:29 a.m. | 29 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61859 - V-SFT VS6ComFile Out-of-Bounds Write Vulnerability
CVE ID : CVE-2025-61859
Published : Oct. 10, 2025, 10:33 a.m. | 25 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61859
Published : Oct. 10, 2025, 10:33 a.m. | 25 minutes ago
Description : An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61860 - V-SFT Out-of-Bounds Read Vulnerability
CVE ID : CVE-2025-61860
Published : Oct. 10, 2025, 10:36 a.m. | 22 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61860
Published : Oct. 10, 2025, 10:36 a.m. | 22 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11189 - CVE-2025-11189
CVE ID : CVE-2025-11189
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11189
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-11190 - CVE-2025-11190
CVE ID : CVE-2025-11190
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-11190
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61861 - V-SFT VS6ComFile Out-of-Bounds Read Vulnerability
CVE ID : CVE-2025-61861
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61861
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61862 - V-SFT Out-of-Bounds Read Vulnerability
CVE ID : CVE-2025-61862
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61862
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61863 - V-SFT VS6ComFile OOB Read Arbitrary Code Execution Vulnerability
CVE ID : CVE-2025-61863
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-61863
Published : Oct. 10, 2025, 11:15 a.m. | 3 hours, 44 minutes ago
Description : An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...