Browse CVEs
145,146 medium severity vulnerabilities
| CVE ID | Title | Severity | CVSS | Risk | Patch | Published |
|---|---|---|---|---|---|---|
| CVE-2025-66258 | Stored Cross-Site Scripting via XML Injection in DB Elect... | Medium | 5.4 | Low Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-62728 | SQL injection vulnerability in Hive Metastore Server (HMS... | Medium | 5.4 | Medium Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-65675 | Stored Cross site scripting (XSS) vulnerability in Classr... | Medium | 5.4 | High Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-65676 | Stored Cross site scripting (XSS) vulnerability in Classr... | Medium | 5.4 | High Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-66030 | Forge (also called `node-forge`) is a native implementati... | Medium | 5.3 | Medium Risk | Partial | 26-Nov-25 |
| CVE-2025-66025 | Caido is a web security auditing toolkit. Prior to versio... | Medium | 4.3 | Low Risk | Patched | 26-Nov-25 |
| CVE-2025-65239 | Incorrect access control in the /aux1/ocussd/trace endpoi... | Medium | 4.3 | Low Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-65670 | An Insecure Direct Object Reference (IDOR) in classroomio... | Medium | 4.3 | High Risk | Unpatched (19d) | 26-Nov-25 |
| CVE-2025-6195 | GitLab has remediated an issue in GitLab EE affecting all... | Medium | 4.3 | Low Risk | Patched | 26-Nov-25 |
| CVE-2025-33190 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT f... | Medium | 6.7 | Low Risk | Unpatched (20d) | 25-Nov-25 |