CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-2068

    Last Modified: 15 Apr 2026

    An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.

    Published: 25 Apr 2025
    5.5
    Medium

    CVE-2024-56156

    Last Modified: 3 Feb 2026

    Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site scripting attacks and potential remote code execution under certain circumstances. This issue has been patched in version 2.20.13.

    Published: 25 Apr 2025
    7.6
    High

    CVE-2025-43862

    Last Modified: 1 Aug 2025

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make unauthorized access and changes on the APPSs. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can access Orchestration of the APPs.

    Published: 25 Apr 2025
    10
    Critical

    CVE-2025-32432

    Last Modified: 21 Mar 2026

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

    Published: 25 Apr 2025
    5.3
    Medium

    CVE-2025-32045

    Last Modified: 24 Jun 2025

    A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32044

    Last Modified: 24 Jun 2025

    A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3647

    Last Modified: 24 Jun 2025

    A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3645

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3644

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-3643

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

    Published: 25 Apr 2025
    8.8
    High

    CVE-2025-3642

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

    Published: 25 Apr 2025
    8.8
    High

    CVE-2025-3641

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3640

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

    Published: 25 Apr 2025
    8.8
    High

    CVE-2025-3638

    Last Modified: 16 Jun 2025

    A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

    Published: 25 Apr 2025
    3.1
    Low

    CVE-2025-3637

    Last Modified: 24 Jun 2025

    A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3636

    Last Modified: 24 Jun 2025

    A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

    Published: 25 Apr 2025
    3.5
    Low

    CVE-2025-3635

    Last Modified: 24 Jun 2025

    A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3628

    Last Modified: 24 Jun 2025

    A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3627

    Last Modified: 24 Jun 2025

    A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

    Published: 25 Apr 2025
    7.1
    High

    CVE-2025-3625

    Last Modified: 24 Jun 2025

    A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

    Published: 25 Apr 2025
    3.5
    Low

    CVE-2025-46618

    Last Modified: 16 May 2025

    In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

    Published: 25 Apr 2025
    4.9
    Medium

    CVE-2025-46433

    Last Modified: 16 May 2025

    In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-46432

    Last Modified: 16 May 2025

    In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-43016

    Last Modified: 1 Oct 2025

    In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

    Published: 25 Apr 2025
    4.3
    Medium

    CVE-2025-3634

    Last Modified: 24 Jun 2025

    A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

    Published: 25 Apr 2025
    8.3
    High

    CVE-2025-3260

    Last Modified: 15 Apr 2026

    A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources.

    Published: 25 Apr 2025
    7.7
    High

    CVE-2024-6199

    Last Modified: 15 Apr 2026

    An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

    Published: 25 Apr 2025
    7.7
    High

    CVE-2024-6198

    Last Modified: 15 Apr 2026

    The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted HTTP request to exploit a buffer overflow on the modem.

    Published: 25 Apr 2025
    9.8
    Critical

    CVE-2025-2470

    Last Modified: 20 Apr 2026

    The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

    Published: 25 Apr 2025
    8.1
    High

    CVE-2024-11917

    Last Modified: 15 Apr 2026

    The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated attackers to log in as the first connected Xing user, or any connected Xing user if the Xing id is known. It is also possible for unauthenticated attackers to log in as the first connected Google user if the user has logged in, without subsequently logging out, in thirty days. The vulnerability was partially patched in version 2.8.4.

    Published: 25 Apr 2025
    5.3
    Medium

    CVE-2025-3912

    Last Modified: 22 Apr 2026

    The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to read the value of the plugin's settings, including API keys for integrated services.

    Published: 25 Apr 2025
    5.5
    Medium

    CVE-2025-2986

    Last Modified: 28 Aug 2025

    IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-1565

    Last Modified: 20 Apr 2026

    The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 25 Apr 2025
    8.8
    High

    CVE-2025-1279

    Last Modified: 21 Apr 2026

    The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-3870

    Last Modified: 21 Apr 2026

    The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to missing or incorrect nonce validation on the 1-decembrie-1918/1-decembrie-1918.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-46535

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0.

    Published: 25 Apr 2025
    6.5
    Medium

    CVE-2025-46482

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a through <= 2.0.10.

    Published: 25 Apr 2025
    5.3
    Medium

    CVE-2025-3743

    Last Modified: 20 Apr 2026

    The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

    Published: 25 Apr 2025
    8.8
    High

    CVE-2025-2238

    Last Modified: 22 Apr 2026

    The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator-level.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-3868

    Last Modified: 22 Apr 2026

    The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-3867

    Last Modified: 22 Apr 2026

    The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-3866

    Last Modified: 15 Apr 2026

    The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-0671

    Last Modified: 29 Apr 2025

    The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Apr 2025
    5.3
    Medium

    CVE-2025-3923

    Last Modified: 20 Apr 2026

    The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to extract sensitive data including files protected by the plugin if the attacker can determine the file name.

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-3861

    Last Modified: 15 Apr 2026

    The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of media.

    Published: 25 Apr 2025
    4.9
    Medium

    CVE-2025-2580

    Last Modified: 22 Apr 2026

    The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-3511

    Last Modified: 27 Aug 2026

    Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Series CC-Link IE TSN Master/Local Module, MELSEC iQ-R Series Ethernet Interface Module, CC-Link IE TSN Master/Local Station Communication LSI CP610, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module, MELSEC iQ-F Series FX5 Ethernet Module, MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, and MELSEC iQ-R Series CPU module allows a remote unauthenticated attacker to cause a Denial of Service condition in the products by sending specially crafted UDP packets.

    Published: 25 Apr 2025
    6.4
    Medium

    CVE-2025-3752

    Last Modified: 21 Apr 2026

    The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2025-46475 may be a duplicate of this.

    Published: 25 Apr 2025
    6.5
    Medium

    CVE-2025-3775

    Last Modified: 21 Apr 2026

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, and can be used to query and modify information from internal services.

    Published: 25 Apr 2025
    8.2
    High

    CVE-2025-43865

    Last Modified: 15 Apr 2026

    React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.

    Published: 25 Apr 2025