CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-26992

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue affects Landing Page Cat: from n/a through <= 1.7.8.

    Published: 15 Apr 2025
    3.7
    Low

    CVE-2025-32943

    Last Modified: 10 Oct 2025

    The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.

    Published: 15 Apr 2025
    5.5
    Medium

    CVE-2025-1688

    Last Modified: 15 Apr 2026

    Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. The system configuration password is an additional, optional protection that is enabled on the Management Server. To mitigate the issue, we highly recommend updating system configuration password via GUI with a standard procedure. Any system upgraded with 2024 R1 or 2024 R2 release installer is vulnerable to this issue. Systems upgraded from 2023 R3 or older with version 2025 R1 and newer are not affected.

    Published: 15 Apr 2025
    6.4
    Medium

    CVE-2025-2083

    Last Modified: 21 Apr 2026

    The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 15 Apr 2025
    8.7
    High

    CVE-2025-3575

    Last Modified: 15 Apr 2026

    Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint.

    Published: 15 Apr 2025
    8.7
    High

    CVE-2025-3574

    Last Modified: 15 Apr 2026

    Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.

    Published: 15 Apr 2025
    9.3
    Critical

    CVE-2025-3579

    Last Modified: 15 Apr 2026

    In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native functions of the framework used, such as Laravel or Symfony. This execution is achieved by Prompt Injection attacks through the /api/<string-chat>/message endpoint, manipulating the content of the ‘content’ parameter.

    Published: 15 Apr 2025
    9.3
    Critical

    CVE-2025-3578

    Last Modified: 15 Apr 2026

    A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the exfiltration of sensitive information, such as details about the software or internal system paths. These actions could be carried out through the misuse of LLM Prompt (chatbot) technology, via the /api/<string-chat>/message endpoint, by manipulating the contents of the ‘content’ parameter.

    Published: 15 Apr 2025
    2.6
    Low

    CVE-2024-45712

    Last Modified: 18 Nov 2025

    SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.

    Published: 15 Apr 2025
    5.1
    Medium

    CVE-2025-3622

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.

    Published: 15 Apr 2025
    6.4
    Medium

    CVE-2025-2225

    Last Modified: 20 Apr 2026

    The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 1.6.9.

    Published: 15 Apr 2025
    5.3
    Medium

    CVE-2025-3573

    Last Modified: 15 Apr 2026

    Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.

    Published: 15 Apr 2025
    6.7
    Medium

    CVE-2025-29984

    Last Modified: 26 Feb 2026

    Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 15 Apr 2025
    6.7
    Medium

    CVE-2025-29983

    Last Modified: 26 Feb 2026

    Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 15 Apr 2025
    5.1
    Medium

    CVE-2025-3613

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Apr 2025
    5.3
    Medium

    CVE-2025-3612

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Apr 2025
    4.8
    Medium

    CVE-2024-13610

    Last Modified: 29 Apr 2025

    The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 Apr 2025
    4.8
    Medium

    CVE-2024-13207

    Last Modified: 29 Apr 2025

    The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 Apr 2025
    4.9
    Medium

    CVE-2025-3470

    Last Modified: 22 Apr 2026

    The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-24949

    Last Modified: 14 Oct 2025

    In JotUrl 2.0, is possible to bypass security requirements during the password change process.

    Published: 15 Apr 2025
    5.9
    Medium

    CVE-2025-3576

    Last Modified: 30 Jun 2026

    A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.

    Published: 15 Apr 2025
    6.1
    Medium

    CVE-2025-33026

    Last Modified: 24 Oct 2025

    In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, PeaZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

    Published: 15 Apr 2025
    6.1
    Medium

    CVE-2025-33027

    Last Modified: 24 Oct 2025

    In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-32993

    Last Modified: 15 Apr 2026

    Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.

    Published: 15 Apr 2025
    4
    Medium

    CVE-2025-32996

    Last Modified: 21 Oct 2025

    In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-28136

    Last Modified: 29 Apr 2025

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-28145

    Last Modified: 1 May 2025

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.

    Published: 15 Apr 2025
    5.9
    Medium

    CVE-2025-28198

    Last Modified: 22 Apr 2025

    A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.

    Published: 15 Apr 2025
    4.3
    Medium

    CVE-2025-29705

    Last Modified: 22 Apr 2025

    code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.

    Published: 15 Apr 2025
    4
    Medium

    CVE-2025-32997

    Last Modified: 21 Oct 2025

    In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.

    Published: 15 Apr 2025
    6.1
    Medium

    CVE-2025-33028

    Last Modified: 15 Apr 2026

    In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, WinZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: a third party has reported that this is a false positive, and has observed that the original CVE-2025-33028.md file has been deleted on GitHub. Also, this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2020-18243

    Last Modified: 22 Apr 2025

    SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo-view-case.php.

    Published: 15 Apr 2025
    9.1
    Critical

    CVE-2021-27289

    Last Modified: 15 Apr 2026

    A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile application used to monitor the network.

    Published: 15 Apr 2025
    7.3
    High

    CVE-2024-36842

    Last Modified: 15 Apr 2026

    An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component.

    Published: 15 Apr 2025
    5.9
    Medium

    CVE-2024-44843

    Last Modified: 25 Apr 2025

    An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

    Published: 15 Apr 2025
    6.4
    Medium

    CVE-2024-49200

    Last Modified: 30 Apr 2025

    An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.

    Published: 15 Apr 2025
    7.2
    High

    CVE-2024-50960

    Last Modified: 25 Apr 2025

    A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-22900

    Last Modified: 22 Apr 2025

    Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

    Published: 15 Apr 2025
    4.6
    Medium

    CVE-2025-22903

    Last Modified: 22 Apr 2025

    TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.

    Published: 15 Apr 2025
    5.6
    Medium

    CVE-2025-22911

    Last Modified: 23 Apr 2025

    RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-24948

    Last Modified: 22 Apr 2025

    In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-25456

    Last Modified: 22 Apr 2025

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.

    Published: 15 Apr 2025
    4.6
    Medium

    CVE-2025-25458

    Last Modified: 22 Apr 2025

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

    Published: 15 Apr 2025
    4.6
    Medium

    CVE-2025-25453

    Last Modified: 22 Apr 2025

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

    Published: 15 Apr 2025
    6.8
    Medium

    CVE-2025-27892

    Last Modified: 23 Apr 2025

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-27980

    Last Modified: 22 May 2025

    cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-28100

    Last Modified: 22 Apr 2025

    A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

    Published: 15 Apr 2025
    9.8
    Critical

    CVE-2025-28137

    Last Modified: 29 Apr 2025

    The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-28142

    Last Modified: 1 May 2025

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.

    Published: 15 Apr 2025
    6.5
    Medium

    CVE-2025-28143

    Last Modified: 1 May 2025

    Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.

    Published: 15 Apr 2025