CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-13569

    Last Modified: 7 May 2025

    The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 22 Apr 2025
    6.7
    Medium

    CVE-2025-1732

    Last Modified: 26 Feb 2026

    An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.

    Published: 22 Apr 2025
    7.8
    High

    CVE-2025-1731

    Last Modified: 26 Feb 2026

    An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token. Modifying the system configuration is only possible if the administrator has not logged out and the token remains valid.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-3856

    Last Modified: 15 Oct 2025

    A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-3855

    Last Modified: 1 Aug 2025

    A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of the argument profile_image_file leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Apr 2025
    8.6
    High

    CVE-2025-3854

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to buffer overflow. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Other functions might be affected as well.

    Published: 22 Apr 2025
    6.3
    Medium

    CVE-2025-3850

    Last Modified: 15 Oct 2025

    A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-43949

    Last Modified: 15 Apr 2026

    MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-43951

    Last Modified: 15 Apr 2026

    LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-29621

    Last Modified: 15 Apr 2026

    Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.

    Published: 22 Apr 2025
    9.3
    Critical

    CVE-2024-58250

    Last Modified: 15 Apr 2026

    The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

    Published: 22 Apr 2025
    6.1
    Medium

    CVE-2025-43952

    Last Modified: 15 Apr 2026

    A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.

    Published: 22 Apr 2025
    5.4
    Medium

    CVE-2024-53569

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2023-43958

    Last Modified: 14 May 2025

    An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-44201

    Last Modified: 15 Aug 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2024-40445

    Last Modified: 23 Jun 2025

    A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2024-40446

    Last Modified: 23 Jun 2025

    An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script

    Published: 22 Apr 2025
    5.4
    Medium

    CVE-2024-53568

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.

    Published: 22 Apr 2025
    6.1
    Medium

    CVE-2025-26159

    Last Modified: 15 Apr 2026

    Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-28026

    Last Modified: 7 May 2025

    TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-28032

    Last Modified: 29 Apr 2025

    TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-28033

    Last Modified: 29 Apr 2025

    TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28037

    Last Modified: 29 Apr 2025

    TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-43946

    Last Modified: 23 Jun 2025

    TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

    Published: 22 Apr 2025
    7.8
    High

    CVE-2025-43950

    Last Modified: 15 Apr 2026

    DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, thus causing a privilege escalation.

    Published: 22 Apr 2025
    7.7
    High

    CVE-2024-33452

    Last Modified: 3 Nov 2025

    An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

    Published: 22 Apr 2025
    6.1
    Medium

    CVE-2023-43378

    Last Modified: 23 Jun 2025

    A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2023-44752

    Last Modified: 24 Apr 2025

    An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.

    Published: 22 Apr 2025
    6.1
    Medium

    CVE-2023-44753

    Last Modified: 24 Apr 2025

    A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2023-44755

    Last Modified: 19 Jun 2025

    Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.

    Published: 22 Apr 2025
    —
    Unknown

    CVE-2025-45959

    Last Modified: 3 Nov 2025

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2024-46546

    Last Modified: 23 Jun 2025

    NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-28031

    Last Modified: 29 Apr 2025

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28024

    Last Modified: 29 Apr 2025

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-28027

    Last Modified: 7 May 2025

    TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-28029

    Last Modified: 7 May 2025

    TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi

    Published: 22 Apr 2025
    8.8
    High

    CVE-2025-28030

    Last Modified: 29 Apr 2025

    TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28034

    Last Modified: 29 Apr 2025

    TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28035

    Last Modified: 29 Apr 2025

    TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28036

    Last Modified: 29 Apr 2025

    TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28038

    Last Modified: 29 Apr 2025

    TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

    Published: 22 Apr 2025
    9.8
    Critical

    CVE-2025-28039

    Last Modified: 29 Apr 2025

    TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

    Published: 22 Apr 2025
    7.5
    High

    CVE-2025-29339

    Last Modified: 19 Jun 2025

    An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via direct attack), triggering a fatal assertion check and causing a daemon crash.

    Published: 22 Apr 2025
    7
    High

    CVE-2025-29547

    Last Modified: 23 Jun 2025

    In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.

    Published: 22 Apr 2025
    6.5
    Medium

    CVE-2025-29743

    Last Modified: 30 Apr 2025

    D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-43947

    Last Modified: 23 Jun 2025

    Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.

    Published: 22 Apr 2025
    7.3
    High

    CVE-2025-43948

    Last Modified: 15 Apr 2026

    Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

    Published: 22 Apr 2025
    5.3
    Medium

    CVE-2025-3849

    Last Modified: 15 Oct 2025

    A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 21 Apr 2025
    3.8
    Low

    CVE-2025-2987

    Last Modified: 1 Sept 2025

    IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 21 Apr 2025
    6.9
    Medium

    CVE-2025-3847

    Last Modified: 15 Oct 2025

    A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 21 Apr 2025