CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2025-28128

    Last Modified: 12 May 2025

    An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

    Published: 25 Apr 2025
    7.1
    High

    CVE-2025-32981

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32982

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32983

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

    Published: 25 Apr 2025
    6.1
    Medium

    CVE-2025-32984

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

    Published: 25 Apr 2025
    9.8
    Critical

    CVE-2025-32985

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-32986

    Last Modified: 27 May 2025

    NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

    Published: 25 Apr 2025
    6.4
    Medium

    CVE-2025-46544

    Last Modified: 15 Oct 2025

    In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

    Published: 25 Apr 2025
    3.5
    Low

    CVE-2025-46546

    Last Modified: 16 Oct 2025

    In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.

    Published: 25 Apr 2025
    5.4
    Medium

    CVE-2025-46547

    Last Modified: 16 Oct 2025

    In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.

    Published: 25 Apr 2025
    6.8
    Medium

    CVE-2025-46599

    Last Modified: 15 Apr 2026

    CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.

    Published: 25 Apr 2025
    7.5
    High

    CVE-2025-46613

    Last Modified: 15 Apr 2026

    OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

    Published: 25 Apr 2025
    9.9
    Critical

    CVE-2025-46616

    Last Modified: 15 Apr 2026

    Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.

    Published: 25 Apr 2025
    7.2
    High

    CVE-2025-46617

    Last Modified: 15 Apr 2026

    Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.

    Published: 25 Apr 2025
    8.5
    High

    CVE-2025-2185

    Last Modified: 15 Apr 2026

    ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

    Published: 24 Apr 2025
    8.7
    High

    CVE-2025-3606

    Last Modified: 15 Apr 2026

    Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be used to further compromise the device.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46275

    Last Modified: 15 Apr 2026

    WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46274

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46273

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46272

    Last Modified: 15 Apr 2026

    WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-46271

    Last Modified: 15 Apr 2026

    UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-1294

    Last Modified: 22 Apr 2026

    The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-3749

    Last Modified: 22 Apr 2026

    The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Apr 2025
    4.4
    Medium

    CVE-2025-43861

    Last Modified: 19 Sept 2025

    ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dialog, the payload will be rendered and executed in the context of their own session. This issue has been patched in commit 2f177dc.

    Published: 24 Apr 2025
    4.6
    Medium

    CVE-2022-44759

    Last Modified: 17 Nov 2025

    Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

    Published: 24 Apr 2025
    4.6
    Medium

    CVE-2022-44760

    Last Modified: 17 Nov 2025

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

    Published: 24 Apr 2025
    3.2
    Low

    CVE-2023-37516

    Last Modified: 17 Nov 2025

    Missing "no cache" headers in HCL Leap permits user directory information to be cached.

    Published: 24 Apr 2025
    3.2
    Low

    CVE-2024-30127

    Last Modified: 17 Nov 2025

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

    Published: 24 Apr 2025
    9.3
    Critical

    CVE-2025-26382

    Last Modified: 15 Apr 2026

    Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue

    Published: 24 Apr 2025
    9.1
    Critical

    CVE-2025-43859

    Last Modified: 15 Apr 2026

    h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue.

    Published: 24 Apr 2025
    9.2
    Critical

    CVE-2025-43858

    Last Modified: 15 Apr 2026

    YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2.

    Published: 24 Apr 2025
    10
    Critical

    CVE-2025-31324

    Last Modified: 26 Feb 2026

    SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

    Published: 24 Apr 2025
    7.1
    High

    CVE-2023-37534

    Last Modified: 17 Nov 2025

    Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

    Published: 24 Apr 2025
    5.3
    Medium

    CVE-2023-45720

    Last Modified: 17 Nov 2025

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

    Published: 24 Apr 2025
    6.3
    Medium

    CVE-2024-30113

    Last Modified: 17 Nov 2025

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

    Published: 24 Apr 2025
    3.7
    Low

    CVE-2024-30114

    Last Modified: 17 Nov 2025

    Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2024-30147

    Last Modified: 17 Nov 2025

    Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

    Published: 24 Apr 2025
    4.1
    Medium

    CVE-2024-30148

    Last Modified: 17 Nov 2025

    Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

    Published: 24 Apr 2025
    5.4
    Medium

    CVE-2025-46498

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-46473

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Prisna Social Counter social-counter allows Object Injection.This issue affects Social Counter: from n/a through <= 2.0.5.

    Published: 24 Apr 2025
    5.9
    Medium

    CVE-2025-46523

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1.

    Published: 24 Apr 2025
    7.1
    High

    CVE-2025-46507

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes unsafe-mimetypes allows Stored XSS.This issue affects Unsafe Mimetypes: from n/a through <= 0.1.4.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-46481

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This issue affects Flickr Shortcode Importer: from n/a through <= 2.2.3.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-46447

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFable Fable Extra fable-extra allows DOM-Based XSS.This issue affects Fable Extra: from n/a through <= 1.0.6.

    Published: 24 Apr 2025
    4.9
    Medium

    CVE-2025-46531

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4.

    Published: 24 Apr 2025
    4.3
    Medium

    CVE-2025-46519

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Downloader: from n/a through <= 1.3.1.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-46511

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Derek Springer BeerXML Shortcode beerxml-shortcode allows Server Side Request Forgery.This issue affects BeerXML Shortcode: from n/a through <= 0.7.1.

    Published: 24 Apr 2025
    4.9
    Medium

    CVE-2025-46503

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in josheli Simple Google Photos Grid simple-google-photos-grid allows Server Side Request Forgery.This issue affects Simple Google Photos Grid: from n/a through <= 1.5.

    Published: 24 Apr 2025
    5.3
    Medium

    CVE-2025-46489

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce wc-bulk-assign-linked-products allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk Assign Linked Products For WooCommerce: from n/a through <= 2.1.

    Published: 24 Apr 2025
    5.3
    Medium

    CVE-2025-46485

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page wp-customize-login-page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Customize Login Page: from n/a through <= 1.6.5.

    Published: 24 Apr 2025