CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2025-4009

    Last Modified: 15 Apr 2026

    The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz. This web interface has two endpoints that are vulnerable to arbitrary command injection (CVE-2025-4009, CVE-2025-10364) and the authentication mechanism has a flaw leading to authentication bypass (CVE-2025-10365). CVE-2025-4009 covers the command injection in feature-transfer-import.php CVE-2025-10364 covers the command injection in feature-transfer-export.php Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.

    Published: 28 May 2025
    4.8
    Medium

    CVE-2025-5025

    Last Modified: 30 Jul 2025

    libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.

    Published: 28 May 2025
    6.5
    Medium

    CVE-2025-4947

    Last Modified: 26 Jun 2025

    libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

    Published: 28 May 2025
    8.8
    High

    CVE-2025-4800

    Last Modified: 20 Apr 2026

    The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server, which may make remote code execution possible.

    Published: 28 May 2025
    4.9
    Medium

    CVE-2025-25029

    Last Modified: 28 Aug 2025

    IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

    Published: 28 May 2025
    4.3
    Medium

    CVE-2025-25026

    Last Modified: 28 Aug 2025

    IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

    Published: 28 May 2025
    4.3
    Medium

    CVE-2025-25025

    Last Modified: 26 Aug 2025

    IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 28 May 2025
    6.1
    Medium

    CVE-2025-32802

    Last Modified: 15 Apr 2026

    Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

    Published: 28 May 2025
    7.8
    High

    CVE-2025-32801

    Last Modified: 15 Apr 2026

    Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

    Published: 28 May 2025
    3.2
    Low

    CVE-2025-48931

    Last Modified: 3 Oct 2025

    The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

    Published: 28 May 2025
    5.3
    Medium

    CVE-2025-48927

    Last Modified: 26 Feb 2026

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

    Published: 28 May 2025
    6.5
    Medium

    CVE-2024-57336

    Last Modified: 15 Apr 2026

    Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.

    Published: 28 May 2025
    6.5
    Medium

    CVE-2024-57337

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.

    Published: 28 May 2025
    6.5
    Medium

    CVE-2024-57338

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.

    Published: 28 May 2025
    4
    Medium

    CVE-2025-48928

    Last Modified: 26 Feb 2026

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

    Published: 28 May 2025
    7.2
    High

    CVE-2025-30087

    Last Modified: 3 Nov 2025

    Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.

    Published: 28 May 2025
    7.2
    High

    CVE-2025-31500

    Last Modified: 9 Jun 2025

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

    Published: 28 May 2025
    7.2
    High

    CVE-2025-31501

    Last Modified: 9 Jun 2025

    Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

    Published: 28 May 2025
    4
    Medium

    CVE-2025-32803

    Last Modified: 15 Apr 2026

    In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

    Published: 28 May 2025
    9.8
    Critical

    CVE-2025-45343

    Last Modified: 3 Jun 2025

    An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.

    Published: 28 May 2025
    8.6
    High

    CVE-2025-45997

    Last Modified: 9 Jun 2025

    Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.

    Published: 28 May 2025
    5.3
    Medium

    CVE-2025-47748

    Last Modified: 19 Jun 2025

    Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

    Published: 28 May 2025
    6.5
    Medium

    CVE-2025-48746

    Last Modified: 24 Jun 2025

    Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

    Published: 28 May 2025
    5
    Medium

    CVE-2025-48747

    Last Modified: 19 Jun 2025

    Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

    Published: 28 May 2025
    9.1
    Critical

    CVE-2025-48749

    Last Modified: 18 Jun 2025

    Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.

    Published: 28 May 2025
    4.3
    Medium

    CVE-2025-48925

    Last Modified: 22 Oct 2025

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

    Published: 28 May 2025
    4.3
    Medium

    CVE-2025-48926

    Last Modified: 22 Oct 2025

    The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

    Published: 28 May 2025
    4
    Medium

    CVE-2025-48929

    Last Modified: 22 Oct 2025

    The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

    Published: 28 May 2025
    2.8
    Low

    CVE-2025-48930

    Last Modified: 22 Oct 2025

    The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.

    Published: 28 May 2025
    5.5
    Medium

    CVE-2024-45094

    Last Modified: 26 Aug 2025

    IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 27 May 2025
    2.6
    Low

    CVE-2025-2826

    Last Modified: 15 Apr 2026

    n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The two symptoms of this issue on the affected release and platform are: * Packets which should be permitted may be dropped and, * Packets which should be dropped may be permitted.

    Published: 27 May 2025
    5.3
    Medium

    CVE-2025-2796

    Last Modified: 15 Apr 2026

    On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability. Note: this issue does not affect VXLANSec or MACSec encryption functionality.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2024-11185

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

    Published: 27 May 2025
    10
    Critical

    CVE-2025-32440

    Last Modified: 11 Jul 2025

    NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-40911

    Last Modified: 15 Apr 2026

    Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses. Leading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation. Net::CIDR::Set used code from Net::CIDR::Lite, which had a similar vulnerability CVE-2021-47154.

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-5067

    Last Modified: 29 May 2025

    Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-5281

    Last Modified: 29 May 2025

    Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-5066

    Last Modified: 29 May 2025

    Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-5065

    Last Modified: 29 May 2025

    Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-5064

    Last Modified: 29 May 2025

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 27 May 2025
    8.8
    High

    CVE-2025-5280

    Last Modified: 26 Feb 2026

    Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 27 May 2025
    8.8
    High

    CVE-2025-5063

    Last Modified: 26 Feb 2026

    Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 27 May 2025
    7
    High

    CVE-2025-5279

    Last Modified: 15 Apr 2026

    When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. An insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. This issue has been addressed in driver version 2.1.7. Users should upgrade to address this issue and ensure any forked or derivative code is patched to incorporate the new fixes.

    Published: 27 May 2025
    Unknown

    CVE-2025-48876

    Last Modified: 3 Sept 2025

    This CVE is a duplicate of another CVE.

    Published: 27 May 2025
    Unknown

    CVE-2025-48870

    Last Modified: 30 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47057. Reason: This candidate is a duplicate of CVE-2024-47057. Notes: All CVE users should reference CVE-2024-47057 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 27 May 2025
    Unknown

    CVE-2025-48871

    Last Modified: 30 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47056. Reason: This candidate is a duplicate of CVE-2024-47056. Notes: All CVE users should reference CVE-2024-47056 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 27 May 2025
    Unknown

    CVE-2025-48872

    Last Modified: 30 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47055. Reason: This candidate is a duplicate of CVE-2024-47055. Notes: All CVE users should reference CVE-2024-47055 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 27 May 2025
    Unknown

    CVE-2025-48873

    Last Modified: 30 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-5256. Reason: This candidate is a duplicate of CVE-2025-5256. Notes: All CVE users should reference CVE-2025-5256 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 27 May 2025
    Unknown

    CVE-2025-48874

    Last Modified: 30 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-5257. Reason: This candidate is a duplicate of CVE-2025-5257. Notes: All CVE users should reference CVE-2025-5257 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-5283

    Last Modified: 3 Nov 2025

    Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 27 May 2025