CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2025-34131

    Last Modified: 2 Jan 2026

    This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

    Published: 15 Apr 2025
    —
    Unknown

    CVE-2025-34137

    Last Modified: 2 Jan 2026

    This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

    Published: 15 Apr 2025
    —
    Unknown

    CVE-2025-34122

    Last Modified: 2 Jan 2026

    This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

    Published: 15 Apr 2025
    —
    Unknown

    CVE-2025-34094

    Last Modified: 2 Jan 2026

    This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-30206

    Last Modified: 15 Apr 2026

    Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host machine. This security flaw allows attackers to analyze the source code, discover the embedded secret, and craft legitimate JWT tokens. By forging these tokens, an attacker can successfully bypass authentication mechanisms, impersonate privileged users, and gain unauthorized administrative access. Consequently, this enables full control over the host machine, potentially leading to severe consequences such as sensitive data exposure, unauthorized command execution, privilege escalation, or further lateral movement within the network environment. This issue is patched in version 1.6.1. A workaround for this vulnerability involves replacing the hardcoded secret with a securely generated value and load it from secure configuration storage.

    Published: 15 Apr 2025
    8.3
    High

    CVE-2025-27791

    Last Modified: 15 Apr 2026

    Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to be written anywhere the uid running Collabora Online can write, if such a response was supplied by a malicious WOPI server. By combining this flaw with a Time of Check, Time of Use DNS lookup issue with a WOPI server address under attacker control, it is possible to present such a response to be processed by a Collabora Online instance. This issue has been patched in versions 24.04.13.1, 23.05.19, and 22.05.25.

    Published: 15 Apr 2025
    5.4
    Medium

    CVE-2025-24358

    Last Modified: 15 Apr 2026

    gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests only when it believes the request is being served over TLS. It determines this by inspecting the r.URL.Scheme value. However, this value is never populated for "server" requests per the Go spec, and so this check does not run in practice. This vulnerability allows an attacker who has gained XSS on a subdomain or top level domain to perform authenticated form submissions against gorilla/csrf protected targets that share the same top level domain. This vulnerability is fixed in 1.7.2.

    Published: 15 Apr 2025
    4.9
    Medium

    CVE-2023-5616

    Last Modified: 26 Aug 2025

    In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

    Published: 15 Apr 2025
    2.1
    Low

    CVE-2024-42193

    Last Modified: 9 Oct 2025

    HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.

    Published: 15 Apr 2025
    5.6
    Medium

    CVE-2024-42189

    Last Modified: 9 Oct 2025

    HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

    Published: 15 Apr 2025
    4.8
    Medium

    CVE-2024-42200

    Last Modified: 9 Oct 2025

    HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.

    Published: 15 Apr 2025
    8.5
    High

    CVE-2025-3618

    Last Modified: 14 Jul 2025

    A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.

    Published: 15 Apr 2025
    8.5
    High

    CVE-2025-3617

    Last Modified: 14 Jul 2025

    A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges.

    Published: 15 Apr 2025
    7.3
    High

    CVE-2025-32780

    Last Modified: 15 Apr 2026

    BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execute arbitrary code every time BleachBit is run. This issue has been patched in version 4.9.0.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-32779

    Last Modified: 15 Apr 2026

    E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to the `/backup/import` API endpoint can write arbitrary files to locations outside the intended extraction directory due to a Zip Slip vulnerability. Although the application runs as a non-root user (`185`), limiting direct impact on system-level files, this vulnerability can still be exploited to overwrite application files (e.g., JAR libraries) owned by the application user. This overwrite can potentially lead to Remote Code Execution (RCE) within the application's context. This issue has been patched in version 5.5.0.

    Published: 15 Apr 2025
    5.5
    Medium

    CVE-2025-32776

    Last Modified: 15 Apr 2026

    OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attacker can cause the custom kernel driver to read more bytes than provided by user space. This data will be written into the RGB arguments which will be sent to the USB device. This issue has been patched in v3.10.2.

    Published: 15 Apr 2025
    5.7
    Medium

    CVE-2025-29817

    Last Modified: 13 Feb 2026

    Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

    Published: 15 Apr 2025
    6.3
    Medium

    CVE-2024-11084

    Last Modified: 15 Apr 2026

    Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.

    Published: 15 Apr 2025
    5.2
    Medium

    CVE-2024-13177

    Last Modified: 15 Apr 2026

    Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a symlink of the file “nsinstallation” to escalate the privileges of a different file on the system. This issue affects Netskope Client: before 123.0, before 117.1.11.2310, before 120.1.10.2306.

    Published: 15 Apr 2025
    6.4
    Medium

    CVE-2025-3523

    Last Modified: 20 Apr 2026

    When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.

    Published: 15 Apr 2025
    6.3
    Medium

    CVE-2025-2830

    Last Modified: 20 Apr 2026

    By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when the message is forwarded or edited as a new message. This vulnerability could allow attackers to disclose sensitive information from the victim's system. This vulnerability is not limited to Linux; similar behavior has been observed on Windows as well. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.

    Published: 15 Apr 2025
    6.3
    Medium

    CVE-2025-3522

    Last Modified: 20 Apr 2026

    Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the URL is not validated or sanitized, it can reference internal resources like chrome:// or SMB share file:// links, potentially leading to hashed Windows credential leakage and opening the door to more serious security issues. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-32949

    Last Modified: 21 Oct 2025

    This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb. If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. The yauzl library does not contain any mechanism to detect or prevent extraction of a Zip Bomb https://en.wikipedia.org/wiki/Zip_bomb . Therefore, when using the User Import functionality with a Zip Bomb, PeerTube will try extracting the archive which will cause a disk space resource exhaustion.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-32948

    Last Modified: 21 Oct 2025

    The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-32947

    Last Modified: 21 Oct 2025

    This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.

    Published: 15 Apr 2025
    —
    Unknown

    CVE-2025-33022

    Last Modified: 9 Mar 2026

    The reporter agreed to not assign CVE ID

    Published: 15 Apr 2025
    5.3
    Medium

    CVE-2025-32946

    Last Modified: 21 Oct 2025

    This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-3608

    Last Modified: 20 Apr 2026

    A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability was fixed in Firefox 137.0.2.

    Published: 15 Apr 2025
    4.3
    Medium

    CVE-2025-32945

    Last Modified: 21 Oct 2025

    The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-32944

    Last Modified: 21 Oct 2025

    The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.

    Published: 15 Apr 2025
    7.1
    High

    CVE-2025-31011

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Reflected XSS.This issue affects SimplyRETS Real Estate IDX: from n/a through <= 3.2.2.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-30985

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.

    Published: 15 Apr 2025
    4.3
    Medium

    CVE-2025-30965

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.

    Published: 15 Apr 2025
    5.4
    Medium

    CVE-2025-30964

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6.

    Published: 15 Apr 2025
    7.1
    High

    CVE-2025-30962

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fs-code FS Poster fs-poster allows Reflected XSS.This issue affects FS Poster: from n/a through <= 6.5.8.

    Published: 15 Apr 2025
    4.4
    Medium

    CVE-2025-26990

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1006.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-26982

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube dsgvo-youtube allows DOM-Based XSS.This issue affects DSGVO Youtube: from n/a through <= 1.5.1.

    Published: 15 Apr 2025
    8.8
    High

    CVE-2025-26959

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a through <= 2025.03.24.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-26958

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlog: from n/a through <= 2.4.3.

    Published: 15 Apr 2025
    4.3
    Medium

    CVE-2025-26955

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Industrial Lite: from n/a through <= 1.0.8.

    Published: 15 Apr 2025
    7.1
    High

    CVE-2025-26954

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooEffect 1-jquery-photo-gallery-slideshow-flash allows Reflected XSS.This issue affects ZooEffect: from n/a through <= 1.11.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-26944

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Crocoblock JetPopup jet-popup allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetPopup: from n/a through <= 2.0.11.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-26942

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Crocoblock JetTricks jet-tricks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetTricks: from n/a through <= 1.5.1.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-26894

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mobeen Abdullah Coming Soon, Maintenance Mode site-mode allows PHP Local File Inclusion.This issue affects Coming Soon, Maintenance Mode: from n/a through <= 1.1.1.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-26889

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hockeydata hockeydata LOS hockeydata-los allows PHP Local File Inclusion.This issue affects hockeydata LOS: from n/a through <= 1.2.4.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-26745

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Elements Elementor Addon rselements-lite allows Stored XSS.This issue affects RS Elements Elementor Addon: from n/a through <= 1.1.5.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-26744

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= 2.4.3.

    Published: 15 Apr 2025
    7.1
    High

    CVE-2025-26743

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Query Search Filter advance-wp-query-search-filter allows Reflected XSS.This issue affects Advance WP Query Search Filter: from n/a through <= 1.0.10.

    Published: 15 Apr 2025
    8.8
    High

    CVE-2025-26741

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6.

    Published: 15 Apr 2025
    7.5
    High

    CVE-2025-32929

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through <= 2.0.4.

    Published: 15 Apr 2025