CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2025-30018

    Last Modified: 23 Oct 2025

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.

    Published: 13 May 2025
    10
    Critical

    CVE-2025-30012

    Last Modified: 23 Oct 2025

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which will result in deserialization of data in the application leading to execution of arbitrary OS command on target as SAP Administrator. This vulnerability has High impact on confidentiality, integrity, and availability of the application.

    Published: 13 May 2025
    5.3
    Medium

    CVE-2025-30011

    Last Modified: 23 Oct 2025

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.

    Published: 13 May 2025
    6.1
    Medium

    CVE-2025-30010

    Last Modified: 23 Oct 2025

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application.

    Published: 13 May 2025
    6.1
    Medium

    CVE-2025-30009

    Last Modified: 23 Oct 2025

    he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application

    Published: 13 May 2025
    4.4
    Medium

    CVE-2025-26662

    Last Modified: 15 Apr 2026

    The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-47905

    Last Modified: 15 Apr 2026

    Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-45858

    Last Modified: 23 May 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-45865

    Last Modified: 15 May 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

    Published: 13 May 2025
    6.1
    Medium

    CVE-2025-47204

    Last Modified: 9 Jul 2025

    An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through Cross-Site Request Forgery (CSRF).

    Published: 13 May 2025
    10
    Critical

    CVE-2024-46506

    Last Modified: 17 Jun 2025

    NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

    Published: 13 May 2025
    8.6
    High

    CVE-2024-48766

    Last Modified: 24 Jun 2025

    NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

    Published: 13 May 2025
    4.9
    Medium

    CVE-2024-56526

    Last Modified: 29 Jan 2026

    An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-28056

    Last Modified: 23 Jun 2025

    rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

    Published: 13 May 2025
    7.2
    High

    CVE-2025-28057

    Last Modified: 9 Jul 2025

    owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.

    Published: 13 May 2025
    7.5
    High

    CVE-2025-28055

    Last Modified: 9 Jul 2025

    upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit

    Published: 13 May 2025
    5.1
    Medium

    CVE-2025-44039

    Last Modified: 11 Jul 2025

    CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-44831

    Last Modified: 16 Jun 2025

    EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-45746

    Last Modified: 21 May 2025

    In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and because access to the service console does not result in login access or data access in the context of the application software platform.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-45857

    Last Modified: 11 Jul 2025

    EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-45859

    Last Modified: 16 Jun 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-45861

    Last Modified: 15 May 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2025-45863

    Last Modified: 23 May 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-45864

    Last Modified: 17 Jun 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-45866

    Last Modified: 17 Jun 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-45867

    Last Modified: 17 Jun 2025

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

    Published: 13 May 2025
    9.8
    Critical

    CVE-2023-49641

    Last Modified: 15 Apr 2026

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 12 May 2025
    1.3
    Low

    CVE-2025-46825

    Last Modified: 11 Jul 2025

    Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XSS) Vulnerability in the `name` parameter of the `http://localhost/?controller=ProjectCreationController&action=create` form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. Note that the default content security policy (CSP) blocks the JavaScript attack, though it can be exploited if an instance is badly configured and the software is vulnerable to CSS injection because of the unsafe-inline on the default CSP. Version 1.2.45 contains a fix for the issue.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31220

    Last Modified: 28 Apr 2026

    A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to read sensitive location information.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-24258

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain root privileges.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31236

    Last Modified: 28 Apr 2026

    An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    8
    High

    CVE-2025-24223

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-24274

    Last Modified: 28 Apr 2026

    An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

    Published: 12 May 2025
    5.3
    Medium

    CVE-2025-31241

    Last Modified: 28 Apr 2026

    A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may cause an unexpected app termination.

    Published: 12 May 2025
    4.7
    Medium

    CVE-2025-31257

    Last Modified: 12 May 2026

    This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31256

    Last Modified: 28 Apr 2026

    The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5. Hot corner may unexpectedly reveal a user’s deleted notes.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-24111

    Last Modified: 28 Apr 2026

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31217

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-31240

    Last Modified: 28 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-24222

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-31237

    Last Modified: 28 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31260

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-31221

    Last Modified: 28 Apr 2026

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to leak memory.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-31247

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31210

    Last Modified: 28 Apr 2026

    The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead to a denial-of-service.

    Published: 12 May 2025
    4.3
    Medium

    CVE-2025-31206

    Last Modified: 2 Apr 2026

    A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-30440

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass ASLR.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31251

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31226

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-24225

    Last Modified: 28 Apr 2026

    An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may lead to user interface spoofing.

    Published: 12 May 2025