CVE Severity Distribution (Last 30 Days)
Found 10 CVEs in the last 30 days.
CVE-2025-6218
HIGH
CVSS: 7.8
EPSS: 90.5%
VulnCheck KEV
PoC Available
CWE-22
T1083
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
Published: 2025-06-21
CVE-2025-62188
HIGH
CVSS: 7.5
EPSS: 0.5%
CWE-200
T1005
T1083
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.
This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.
This issue affects Apache DolphinScheduler versions 3.1.*.
Users are recommended to upgrade to:
* version ≥ 3.2.0 if using 3.1.x
As a temporary workaround, users who cannot upgrade immediately may restrict the exposed management endpoints by setting the following environment variable:
```
MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE=health,metrics,prometheus
```
Alternatively, add the following configuration to the application.yaml file:
```
management:
endpoints:
web:
exposure:
include: health,metrics,prometheus
```
This issue has been reported as CVE-2023-48796:
https://cveprocess.apache.org/cve5/CVE-2023-48796
Published: 2026-04-09
CVE-2025-62185
MEDIUM
CVSS: 6.7
EPSS: 0.2%
CWE-427
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.
Published: 2025-10-07
CVE-2025-62186
MEDIUM
CVSS: 6.7
EPSS: 0.1%
CWE-829
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.
Published: 2025-10-07
CVE-2025-62181
MEDIUM
CVSS: 5.3
EPSS: 0.4%
CWE-204
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication feature and other more secure authentication mechanisms are recommended. A fix is being provided in the 24.1.4, 24.2.4, and 25.1.1 patch releases. Please note: Basic credentials authentication service type is deprecated started in 24.2 version: https://docs.pega.com/bundle/platform/page/platform/release-notes/security/whats-new-security-242.html.
Published: 2025-12-10
CVE-2025-62189
MEDIUM
CVSS: 4.3
EPSS: 0.2%
CWE-863
T1078
LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.
Published: 2025-11-21
CVE-2025-62184
LOW
CVSS: 3.4
EPSS: 0.3%
CWE-79
T1189
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.
Published: 2026-03-31
CVE-2025-62187
LOW
CVSS: 2.9
EPSS: 0.2%
CWE-23
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
Published: 2025-10-07
CVE-2025-62182
UNKNOWN
EPSS: 0.3%
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
Published: 2026-01-13
CVE-2025-62183
UNKNOWN
EPSS: 0.3%
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality and Integrity are low.
Published: 2026-02-17