Home Embedded Vulns General Vulns
CVE ID Description Severity Published Type
CVE-2025-71177 LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package cre… Medium (5.4) 2026-01-23 General Purpose
CVE-2025-67231 A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary… Medium (5.9) 2026-01-23 General Purpose
CVE-2025-67230 Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with render… High (7.1) 2026-01-23 General Purpose
CVE-2025-67229 An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unaut… Critical (9.8) 2026-01-23 General Purpose
CVE-2022-25369 An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authenticatio… Critical (9.8) 2026-01-23 General Purpose