CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-43864

    Last Modified: 15 Apr 2026

    React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application. This issue has been patched in version 7.5.2.

    Published: 25 Apr 2025
    6.4
    Medium

    CVE-2025-46595

    Last Modified: 15 Apr 2026

    An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigated by the fact that an attacker must have a role with permission to create links on the website, for example: create or edit comments or content with a filtered text format.

    Published: 25 Apr 2025
    9.8
    Critical

    CVE-2025-32980

    Last Modified: 15 Apr 2026

    NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.

    Published: 25 Apr 2025
    6.5
    Medium

    CVE-2025-28076

    Last Modified: 15 Apr 2026

    Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) timeago, (2) user, (3) filter, (4) target, (5) p1, (6) p2, (7) p3, (8) p4, (9) p5, (10) p6, (11) p7, (12) p8, (13) p9, (14) p10, (15) p11, (16) p12, (17) p13, (18) p14, (19) p15, (20) p16, (21) p17, (22) p18, (23) p19, or (24) p20 parameter to /api/management/updateihmsettings; the (25) ID, (26) NAME, (27) CPUTHREADNB, (28) RAMCAP, or (29) DISKCAP parameter to /api/capaplan/savetemplates.

    Published: 25 Apr 2025
    6.5
    Medium

    CVE-2025-28354

    Last Modified: 15 Apr 2026

    An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request.

    Published: 25 Apr 2025
    4.4
    Medium

    CVE-2025-46545

    Last Modified: 15 Oct 2025

    In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

    Published: 25 Apr 2025
    6.5
    Medium

    CVE-2025-32979

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

    Published: 25 Apr 2025
    2.4
    Low

    CVE-2024-57375

    Last Modified: 15 Apr 2026

    Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions.

    Published: 25 Apr 2025
    9.8
    Critical

    CVE-2025-25775

    Last Modified: 28 May 2025

    Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

    Published: 25 Apr 2025
    7
    High

    CVE-2025-28128

    Last Modified: 12 May 2025

    An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

    Published: 25 Apr 2025
    7.1
    High

    CVE-2025-32981

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32982

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32983

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-32984

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

    Published: 25 Apr 2025
    9.8
    Critical

    CVE-2025-32985

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32986

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

    Published: 25 Apr 2025
    6.4
    Medium

    CVE-2025-46544

    Last Modified: 15 Oct 2025

    In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

    Published: 25 Apr 2025
    3.5
    Low

    CVE-2025-46546

    Last Modified: 16 Oct 2025

    In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-46547

    Last Modified: 16 Oct 2025

    In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.

    Published: 25 Apr 2025
    6.8
    Medium

    CVE-2025-46599

    Last Modified: 15 Apr 2026

    CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-46613

    Last Modified: 15 Apr 2026

    OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

    Published: 25 Apr 2025
    9.9
    Critical

    CVE-2025-46616

    Last Modified: 15 Apr 2026

    Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.

    Published: 25 Apr 2025
    7.2
    High

    CVE-2025-46617

    Last Modified: 15 Apr 2026

    Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.

    Published: 25 Apr 2025
    8.5
    High

    CVE-2025-2185

    Last Modified: 15 Apr 2026

    ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

    Published: 24 Apr 2025
    8.7
    High

    CVE-2025-3606

    Last Modified: 15 Apr 2026

    Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be used to further compromise the device.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46275

    Last Modified: 15 Apr 2026

    WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46274

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46273

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46272

    Last Modified: 15 Apr 2026

    WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46271

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-1294

    Last Modified: 22 Apr 2026

    The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-3749

    Last Modified: 22 Apr 2026

    The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Apr 2025
    4.4
    Medium

    CVE-2025-43861

    Last Modified: 19 Sept 2025

    ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dialog, the payload will be rendered and executed in the context of their own session. This issue has been patched in commit 2f177dc.

    Published: 24 Apr 2025
    4.6
    Medium

    CVE-2022-44759

    Last Modified: 17 Nov 2025

    Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

    Published: 24 Apr 2025
    4.6
    Medium

    CVE-2022-44760

    Last Modified: 17 Nov 2025

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

    Published: 24 Apr 2025
    3.2
    Low

    CVE-2023-37516

    Last Modified: 17 Nov 2025

    Missing "no cache" headers in HCL Leap permits user directory information to be cached.

    Published: 24 Apr 2025
    3.2
    Low

    CVE-2024-30127

    Last Modified: 17 Nov 2025

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-26382

    Last Modified: 15 Apr 2026

    Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

    Published: 24 Apr 2025
    9.1
    Critical

    CVE-2025-43859

    Last Modified: 15 Apr 2026

    h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.

    Published: 24 Apr 2025
    9.2
    Critical

    CVE-2025-43858

    Last Modified: 15 Apr 2026

    YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2.

    Published: 24 Apr 2025
    10
    Critical

    CVE-2025-31324

    Last Modified: 26 Feb 2026

    SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

    Published: 24 Apr 2025
    7.1
    High

    CVE-2023-37534

    Last Modified: 17 Nov 2025

    Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

    Published: 24 Apr 2025
    5.3
    Medium

    CVE-2023-45720

    Last Modified: 17 Nov 2025

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

    Published: 24 Apr 2025
    6.3
    Medium

    CVE-2024-30113

    Last Modified: 17 Nov 2025

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

    Published: 24 Apr 2025
    3.7
    Low

    CVE-2024-30114

    Last Modified: 17 Nov 2025

    Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2024-30147

    Last Modified: 17 Nov 2025

    Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

    Published: 24 Apr 2025
    4.1
    Medium

    CVE-2024-30148

    Last Modified: 17 Nov 2025

    Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

    Published: 24 Apr 2025
    5.4
    Medium

    CVE-2025-46498

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-46473

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Prisna Social Counter social-counter allows Object Injection.This issue affects Social Counter: from n/a through <= 2.0.5.

    Published: 24 Apr 2025
    5.9
    Medium

    CVE-2025-46523

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1.

    Published: 24 Apr 2025