Currently trending CVE - Hype Score: 16 - Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
A vulnerability classified as problematic has been found in Pallets Werkzeug up to 3.1.3 on Windows. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper handling of windows device names.
This vulnerability is listed as CVE-2025-66221. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in OpenObserve up to 0.15.x. Affected by this issue is some unknown functionality of the component Organization Invitation Token Handler. The manipulation results in session expiration.
This vulnerability is cataloged as CVE-2025-66223. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in krpano up to 1.23.1. It has been rated as problematic. This affects the function passQueryParameters of the component URL Handler. This manipulation of the argument xml causes cross site scripting.
This vulnerability is handled as CVE-2025-65892. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in xmall 1.1. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-65540. The attack can be launched remotely. No exploit exists.
A vulnerability labeled as problematic has been found in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key
.
The identification of this vulnerability is CVE-2025-6666. The physical device can be targeted for the attack. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability identified as problematic has been detected in Anjaliavv51 Retro up to 2.4.6. Affected is an unknown function. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-66036. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in xmall 1.1. This impacts an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-65540. The attack can be launched remotely. No exploit exists.
A vulnerability was found in krpano up to 1.23.1. It has been rated as problematic. This affects the function passQueryParameters of the component URL Handler. This manipulation of the argument xml causes cross site scripting.
This vulnerability is handled as CVE-2025-65892. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in danny-avila LibreChat up to 0.8.1-rc1. It has been declared as critical. The impacted element is an unknown function of the component OpenAPI Handler. The manipulation results in server-side request forgery.
This vulnerability is known as CVE-2025-66201. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in ricardoboss PubNet up to 1.1.2. It has been classified as critical. The affected element is an unknown function of the file /api/storage/upload. The manipulation of the argument author-id leads to missing authorization.
This vulnerability is traded as CVE-2025-65112. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in shama willitmerge up to 0.2.1 and classified as critical. Impacted is an unknown function of the component User Control. Executing manipulation can lead to command injection.
This vulnerability appears as CVE-2025-66219. The attack may be performed from remote. There is no available exploit.
A vulnerability has been found in jvde-github AIS-catcher up to 0.63 and classified as critical. This issue affects the function AIS::Message. Performing manipulation results in incorrect calculation of buffer size.
This vulnerability is reported as CVE-2025-66216. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in kiteworks MFT up to 9.0.x. This vulnerability affects unknown code. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2025-53897. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Kiteworks MFT up to 9.0.x. This affects an unknown part. This manipulation causes session expiration.
This vulnerability is registered as CVE-2025-53896. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in OpenObserve up to 0.15.x. Affected by this issue is some unknown functionality of the component Organization Invitation Token Handler. The manipulation results in session expiration.
This vulnerability is cataloged as CVE-2025-66223. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Pallets Werkzeug up to 3.1.3 on Windows. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper handling of windows device names.
This vulnerability is listed as CVE-2025-66221. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Kiteworks Core up to 9.0.x. Affected is an unknown function of the component Shared Folder Handler. Executing manipulation can lead to permission issues.
This vulnerability is tracked as CVE-2025-53939. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.