CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-3769

    Last Modified: 21 Apr 2026

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to retrieve appointment details such as customer names and email addresses.

    Published: 14 May 2025
    8.1
    High

    CVE-2025-3834

    Last Modified: 16 Jun 2025

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

    Published: 14 May 2025
    8.1
    High

    CVE-2025-3833

    Last Modified: 30 Sept 2025

    Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

    Published: 14 May 2025
    9.5
    Critical

    CVE-2025-47292

    Last Modified: 15 Apr 2026

    Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by unauthenticated user. Exploitation of this vulnerability can lead to Remote Code Execution. The vulnerability is fixed in commit 812f2a7d271b76deab1175bdaf2be0b8102dd198.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-26864

    Last Modified: 1 Jul 2025

    Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-26795

    Last Modified: 11 Jul 2025

    Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

    Published: 14 May 2025
    9.8
    Critical

    CVE-2024-24780

    Last Modified: 26 Feb 2026

    Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.

    Published: 14 May 2025
    8.6
    High

    CVE-2025-4430

    Last Modified: 15 Apr 2026

    Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).

    Published: 14 May 2025
    8.7
    High

    CVE-2025-2875

    Last Modified: 15 Apr 2026

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.

    Published: 14 May 2025
    5.3
    Medium

    CVE-2024-8988

    Last Modified: 15 Apr 2026

    The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download files uploaded by others users and expose potentially sensitive information.

    Published: 14 May 2025
    5.5
    Medium

    CVE-2024-13940

    Last Modified: 15 Apr 2026

    The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 14 May 2025
    Unknown

    CVE-2025-0020

    Last Modified: 19 May 2025

    “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it is not a vulnerability”

    Published: 14 May 2025
    6.3
    Medium

    CVE-2024-52290

    Last Modified: 11 Jul 2025

    LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Configuration key `Name` (`confKey`) parameter. After this setup, when any user with access to this service (e.g. admin) tries to delete this key, a payload acts in the victim's browser. Version 2.1.0 fixes the issue.

    Published: 14 May 2025
    5.4
    Medium

    CVE-2025-4520

    Last Modified: 21 Apr 2026

    The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.

    Published: 14 May 2025
    9.1
    Critical

    CVE-2025-3623

    Last Modified: 22 Apr 2026

    The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files.

    Published: 14 May 2025
    5.5
    Medium

    CVE-2023-53146

    Last Modified: 5 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: media: dw2102: Fix null-ptr-deref in dw2102_i2c_transfer() In dw2102_i2c_transfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach dw2102_i2c_transfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 950e252cb469 ("[media] dw2102: limit messages to buffer size")

    Published: 14 May 2025
    7.5
    High

    CVE-2025-44879

    Last Modified: 15 Apr 2026

    WS-WN572HP3 V230525 was discovered to contain a buffer overflow in the component /www/cgi-bin/upload.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 14 May 2025
    4.8
    Medium

    CVE-2025-44184

    Last Modified: 28 May 2025

    SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-44024

    Last Modified: 15 Apr 2026

    Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the login form. An attacker can inject malicious JavaScript code into the username or password fields during the login process

    Published: 14 May 2025
    6.1
    Medium

    CVE-2024-45516

    Last Modified: 11 Jun 2025

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, including malformed <img> tags with embedded JavaScript. The vulnerability is triggered when a user views a specially crafted email in the Classic UI, requiring no additional user interaction.

    Published: 14 May 2025
    5.5
    Medium

    CVE-2024-57096

    Last Modified: 30 Oct 2025

    An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.

    Published: 14 May 2025
    5.4
    Medium

    CVE-2024-57273

    Last Modified: 23 Jun 2025

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-26783

    Last Modified: 1 Jul 2025

    An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, W1000, Modem 5300, and Modem 5400. Incorrect handling of undefined values leads to a Denial of Service.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-29689

    Last Modified: 29 May 2025

    A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-29690

    Last Modified: 29 May 2025

    A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.

    Published: 14 May 2025
    5.4
    Medium

    CVE-2025-44186

    Last Modified: 27 May 2025

    SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

    Published: 14 May 2025
    8.1
    High

    CVE-2024-58101

    Last Modified: 15 Apr 2026

    Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.

    Published: 14 May 2025
    5.4
    Medium

    CVE-2024-54779

    Last Modified: 23 Jun 2025

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.

    Published: 14 May 2025
    8.8
    High

    CVE-2024-54780

    Last Modified: 13 Jun 2025

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

    Published: 14 May 2025
    7.5
    High

    CVE-2024-55569

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2024-56427

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds access via malformed RRC packets to the target.

    Published: 14 May 2025
    7.8
    High

    CVE-2025-3931

    Last Modified: 15 Apr 2026

    A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

    Published: 14 May 2025
    4.6
    Medium

    CVE-2025-25370

    Last Modified: 15 Apr 2026

    An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function.

    Published: 14 May 2025
    6.5
    Medium

    CVE-2025-26784

    Last Modified: 25 Jun 2025

    An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

    Published: 14 May 2025
    7.5
    High

    CVE-2025-26785

    Last Modified: 25 Jun 2025

    An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

    Published: 14 May 2025
    9.1
    Critical

    CVE-2025-27891

    Last Modified: 1 Jul 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds reads via malformed NAS packets.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-29686

    Last Modified: 29 May 2025

    A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-29688

    Last Modified: 29 May 2025

    A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.

    Published: 14 May 2025
    6.1
    Medium

    CVE-2025-29691

    Last Modified: 29 May 2025

    A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.

    Published: 14 May 2025
    9.8
    Critical

    CVE-2025-32363

    Last Modified: 15 Apr 2026

    mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

    Published: 14 May 2025
    Unknown

    CVE-2025-47915

    Last Modified: 13 Feb 2026

    reserved but not needed

    Published: 13 May 2025
    8
    High

    CVE-2025-26646

    Last Modified: 26 Feb 2026

    External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

    Published: 13 May 2025
    5.6
    Medium

    CVE-2024-48869

    Last Modified: 15 Apr 2026

    Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2024-47800

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2024-47795

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2024-47550

    Last Modified: 15 Apr 2026

    Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2024-46895

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.2
    Medium

    CVE-2024-45371

    Last Modified: 15 Apr 2026

    Improper access control for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 May 2025
    6.9
    Medium

    CVE-2024-45333

    Last Modified: 15 Apr 2026

    Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 May 2025
    5.7
    Medium

    CVE-2024-45332

    Last Modified: 15 Apr 2026

    Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 13 May 2025