CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2025-32119

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce cardgate allows Blind SQL Injection.This issue affects CardGate Payments for WooCommerce: from n/a through <= 3.2.1.

    Published: 10 Apr 2025
    7.1
    High

    CVE-2025-32116

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master qr-master allows Reflected XSS.This issue affects QR Master: from n/a through <= 1.0.5.

    Published: 10 Apr 2025
    7.1
    High

    CVE-2025-32115

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Content Light popping-content-light allows Reflected XSS.This issue affects Popping Content Light: from n/a through <= 2.4.

    Published: 10 Apr 2025
    7.1
    High

    CVE-2025-32114

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist WordPress 5sterrenspecialist Plugin 5-sterrenspecialist allows Reflected XSS.This issue affects WordPress 5sterrenspecialist Plugin: from n/a through <= 1.4.

    Published: 10 Apr 2025
    8.8
    High

    CVE-2025-31524

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2.

    Published: 10 Apr 2025
    8.1
    High

    CVE-2025-30582

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/CRM dyapress allows PHP Local File Inclusion.This issue affects DyaPress ERP/CRM: from n/a through <= 18.0.2.0.

    Published: 10 Apr 2025
    8.5
    High

    CVE-2025-32687

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magnigenie Review Stars Count For WooCommerce review-stars-count-for-woocommerce allows SQL Injection.This issue affects Review Stars Count For WooCommerce: from n/a through <= 2.0.

    Published: 10 Apr 2025
    8.1
    High

    CVE-2025-32668

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3.

    Published: 10 Apr 2025
    6
    Medium

    CVE-2024-38865

    Last Modified: 21 Aug 2025

    Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact group assigned to their user account and for an event to originate from a host with the same contact group or from an event generated with an unknown host.

    Published: 10 Apr 2025
    8.8
    High

    CVE-2025-3417

    Last Modified: 15 Apr 2026

    The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_set_global_option() function in versions 1.3 to 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 10 Apr 2025
    4.9
    Medium

    CVE-2024-13909

    Last Modified: 15 Apr 2026

    The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 Apr 2025
    7.3
    High

    CVE-2025-2805

    Last Modified: 20 Apr 2026

    The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 10 Apr 2025
    6.5
    Medium

    CVE-2025-2719

    Last Modified: 15 Apr 2026

    The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in versions 1.2.8 to 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.

    Published: 10 Apr 2025
    7.3
    High

    CVE-2025-2809

    Last Modified: 22 Apr 2026

    The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 10 Apr 2025
    6.4
    Medium

    CVE-2024-10894

    Last Modified: 15 Apr 2026

    The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-3494

    Last Modified: 17 Jun 2025

    This CVE ID has been rejected by its CNA as it was not a security issue.

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-3493

    Last Modified: 17 Jun 2025

    This CVE ID has been rejected by its CNA as it was not a security issue.

    Published: 10 Apr 2025
    5.9
    Medium

    CVE-2025-0539

    Last Modified: 2 Jul 2025

    In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.

    Published: 10 Apr 2025
    8.1
    High

    CVE-2025-3102

    Last Modified: 21 Apr 2026

    The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-31943

    Last Modified: 12 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-32087

    Last Modified: 12 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-27941

    Last Modified: 13 Feb 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 10 Apr 2025
    —
    Unknown

    CVE-2025-32737

    Last Modified: 12 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 10 Apr 2025
    5.3
    Medium

    CVE-2025-3489

    Last Modified: 29 Apr 2025

    A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Apr 2025
    3.1
    Low

    CVE-2025-26479

    Last Modified: 15 Jul 2025

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.

    Published: 10 Apr 2025
    3.3
    Low

    CVE-2025-23378

    Last Modified: 15 Jul 2025

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

    Published: 10 Apr 2025
    5.3
    Medium

    CVE-2025-26480

    Last Modified: 13 Jul 2025

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

    Published: 10 Apr 2025
    6.5
    Medium

    CVE-2025-22471

    Last Modified: 15 Jul 2025

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

    Published: 10 Apr 2025
    7
    High

    CVE-2025-26330

    Last Modified: 26 Feb 2026

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.

    Published: 10 Apr 2025
    9.8
    Critical

    CVE-2025-27690

    Last Modified: 26 Feb 2026

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.

    Published: 10 Apr 2025
    6.5
    Medium

    CVE-2024-13896

    Last Modified: 27 Aug 2025

    The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue

    Published: 10 Apr 2025
    7.1
    High

    CVE-2024-13874

    Last Modified: 30 Apr 2025

    The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 10 Apr 2025
    3.1
    Low

    CVE-2025-29989

    Last Modified: 18 Aug 2025

    Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.

    Published: 10 Apr 2025
    8.1
    High

    CVE-2025-27812

    Last Modified: 15 Apr 2026

    MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.

    Published: 10 Apr 2025
    5.3
    Medium

    CVE-2025-32807

    Last Modified: 15 Apr 2026

    A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

    Published: 10 Apr 2025
    4.3
    Medium

    CVE-2025-32728

    Last Modified: 22 May 2025

    In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

    Published: 10 Apr 2025
    4.3
    Medium

    CVE-2025-29150

    Last Modified: 15 Apr 2025

    BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

    Published: 10 Apr 2025
    9
    Critical

    CVE-2025-32743

    Last Modified: 15 Apr 2026

    In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code, because those lookup values lead to incorrect length calculations and incorrect memcpy operations.

    Published: 10 Apr 2025
    9
    Critical

    CVE-2024-58136

    Last Modified: 5 Nov 2025

    Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

    Published: 10 Apr 2025
    8.1
    High

    CVE-2025-27813

    Last Modified: 15 Apr 2026

    MSI Center before 2.0.52.0 has Missing PE Signature Validation.

    Published: 10 Apr 2025
    8.8
    High

    CVE-2025-29017

    Last Modified: 30 Apr 2025

    A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.

    Published: 10 Apr 2025
    5.6
    Medium

    CVE-2025-29088

    Last Modified: 30 Sept 2025

    In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.

    Published: 10 Apr 2025
    6.5
    Medium

    CVE-2025-32386

    Last Modified: 3 Sept 2025

    Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to terminate. This issue has been resolved in Helm v3.17.3.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-32387

    Last Modified: 3 Sept 2025

    Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.17.3.

    Published: 9 Apr 2025
    5
    Medium

    CVE-2025-24375

    Last Modified: 15 Apr 2026

    Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing the full URI, with user and password. The file can be read by a unprivileged user during the operator runtime, due it being created with read permissions (0x644). On other cases, when calling mysql cli, for one specific case when creating the operator users, the DDL contains said users credentials, which can be leak through the same mechanism of a temporary file. All versions prior to revision 221 for kubernetes and revision 338 for machine operators.

    Published: 9 Apr 2025
    8.7
    High

    CVE-2025-30660

    Last Modified: 23 Jan 2026

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).When processing a high rate of specific GRE traffic destined to the device, the respective PFE will hang causing traffic forwarding to stop. When this issue occurs the following logs can be observed: <fpc #> MQSS(0): LI-3: Received a parcel with more than 512B accompanying data CHASSISD_FPC_ASIC_ERROR: ASIC Error detected <...> This issue affects Junos OS: * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S8, * 22.2 versions before 22.2R3-S4, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S2, * 23.4 versions before 23.4R2.

    Published: 9 Apr 2025
    8.7
    High

    CVE-2025-30659

    Last Modified: 23 Jan 2026

    An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for Secure Vector Routing (SVR) receives a specifically malformed packet the PFE will crash and restart. This issue affects Junos OS on SRX Series: * All 21.4 versions, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S6, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2. This issue does not affect versions before 21.4.

    Published: 9 Apr 2025
    8.7
    High

    CVE-2025-30658

    Last Modified: 23 Jan 2026

    A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX platforms with Anti-Virus enabled, if a server sends specific content in the HTTP body of a response to a client request, these packets are queued by Anti-Virus processing in Juniper Buffers (jbufs) which are never released. When these jbufs are exhausted, the device stops forwarding all transit traffic. A jbuf memory leak can be noticed from the following logs: (<node>.)<fpc> Warning: jbuf pool id <#> utilization level (<current level>%) is above <threshold>%! To recover from this issue, the affected device needs to be manually rebooted to free the leaked jbufs. This issue affects Junos OS on SRX Series:  * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S6, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S3, * 24.2 versions before 24.2R2.

    Published: 9 Apr 2025
    6.9
    Medium

    CVE-2025-30657

    Last Modified: 23 Jan 2026

    An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a specific BGP update message, it is correctly processed internally by the routing protocol daemon (rpd), but when it's sent to SRRD it's encoded incorrectly which leads to a crash and momentary interruption of jflow processing until it automatically restarts. This issue does not affect traffic forwarding itself. This issue affects Junos OS:  * All versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3, * 23.2 versions before 23.2R1-S2, 23.2R2. This issue does not affected Junos OS Evolved.

    Published: 9 Apr 2025
    8.7
    High

    CVE-2025-30656

    Last Modified: 23 Jan 2026

    An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If the SIP ALG processes specifically formatted SIP invites, a memory corruption will occur which will lead to a crash of the FPC processing these packets. Although the system will automatically recover with the restart of the FPC, subsequent SIP invites will cause the crash again and lead to a sustained DoS. This issue affects Junos OS on MX Series and SRX Series:  * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S10, * 22.2 versions before 22.2R3-S6, * 22.4 versions before 22.4R3-S5, * 23.2 versions before 23.2R2-S3, * 23.4 versions before 23.4R2-S3, * 24.2 versions before 24.2R1-S2, 24.2R2.

    Published: 9 Apr 2025