CVE-2025-4653 |
Description: Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
CVSS: HIGH (7.0) EPSS Score: 0.57% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-4577 |
Description: The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS: MEDIUM (6.4) EPSS Score: 0.03% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-44044 |
Description: Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.
CVSS: HIGH (7.5) EPSS Score: 0.05% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-44043 |
Description: Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.
EPSS Score: 0.03%
June 10th, 2025 (10 days ago)
|
CVE-2025-43701 |
Description: Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.
This impacts OmniStudio: before version 254.
EPSS Score: 0.04% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-43700 |
Description: Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.
This impacts OmniStudio: before Spring 2025.
EPSS Score: 0.04% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-43699 |
Description: Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for OmniUICard objects.
This impacts OmniStudio: before Spring 2025
EPSS Score: 0.05% SSVC Exploitation: none
June 10th, 2025 (10 days ago)
|
CVE-2025-43698 |
Description: Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects.
This impacts OmniStudio: before Spring 2025
EPSS Score: 0.04%
June 10th, 2025 (10 days ago)
|
CVE-2025-43697 |
Description: Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data.
This impacts OmniStudio: before Spring 2025
EPSS Score: 0.04%
June 10th, 2025 (10 days ago)
|
CVE-2025-43593 |
Description: InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS: HIGH (7.8) EPSS Score: 0.03%
June 10th, 2025 (10 days ago)
|