General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-71177 | LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package cre… | Medium (5.4) | 2026-01-23 | General Purpose |
| CVE-2025-67231 | A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary… | Medium (5.9) | 2026-01-23 | General Purpose |
| CVE-2025-67230 | Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with render… | High (7.1) | 2026-01-23 | General Purpose |
| CVE-2025-67229 | An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unaut… | Critical (9.8) | 2026-01-23 | General Purpose |
| CVE-2022-25369 | An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authenticatio… | Critical (9.8) | 2026-01-23 | General Purpose |