CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-33844

    Last Modified: 16 Aug 2025

    IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 9 Apr 2025
    7.7
    High

    CVE-2025-1968

    Last Modified: 15 Apr 2026

    Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-32381

    Last Modified: 17 Sept 2025

    XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgrammar includes a cache for compiled grammars to increase performance with repeated use of the same grammar. This cache is held in memory. Since the cache is unbounded, a system making use of xgrammar can be abused to fill up a host's memory and case a denial of service. For example, sending many small requests to an LLM inference server with unique JSON schemas would eventually cause this denial of service to occur. This vulnerability is fixed in 0.1.18.

    Published: 9 Apr 2025
    5.3
    Medium

    CVE-2025-31672

    Last Modified: 15 Jul 2025

    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in the zip. In this case, products reading the affected file could read different data because 1 of the zip entries with the duplicate name is selected over another but different products may choose a different zip entry. This issue affects Apache POI poi-ooxml before 5.4.0. poi-ooxml 5.4.0 has a check that throws an exception if zip entries with duplicate file names are found in the input file. Users are recommended to upgrade to version poi-ooxml 5.4.0, which fixes the issue. Please read https://poi.apache.org/security.html for recommendations about how to use the POI libraries securely.

    Published: 9 Apr 2025
    6.3
    Medium

    CVE-2025-30677

    Last Modified: 15 Jul 2025

    Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This vulnerability can lead to unintended exposure of credentials in log files, potentially allowing attackers with access to these logs to obtain Apache Kafka credentials. The vulnerability's impact is limited by the fact that an attacker would need access to the application logs to exploit this issue. This issue affects Apache Pulsar IO's Apache Kafka connectors in all versions before 3.0.11, 3.3.6, and 4.0.4. 3.0.x version users should upgrade to at least 3.0.11. 3.3.x version users should upgrade to at least 3.3.6. 4.0.x version users should upgrade to at least 4.0.4. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.

    Published: 9 Apr 2025
    6.9
    Medium

    CVE-2017-20197

    Last Modified: 15 Apr 2026

    A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The name of the patch is b32bb1b940f82d38fb9310cd66ebe349e20a1d0a. It is recommended to apply a patch to fix this issue.

    Published: 9 Apr 2025
    5.4
    Medium

    CVE-2025-2442

    Last Modified: 15 Apr 2026

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access which could result in the loss of confidentially, integrity and availability when a malicious user, having physical access, sets the radio to the factory default mode.

    Published: 9 Apr 2025
    4.1
    Medium

    CVE-2025-2441

    Last Modified: 15 Apr 2026

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.

    Published: 9 Apr 2025
    4.1
    Medium

    CVE-2025-2440

    Last Modified: 15 Apr 2026

    CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.

    Published: 9 Apr 2025
    8.4
    High

    CVE-2025-2223

    Last Modified: 15 Apr 2026

    CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.

    Published: 9 Apr 2025
    8.2
    High

    CVE-2025-2222

    Last Modified: 15 Apr 2026

    CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.

    Published: 9 Apr 2025
    7.5
    High

    CVE-2025-29870

    Last Modified: 15 Apr 2026

    Missing authentication for critical function vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product configuration information including authentication information.

    Published: 9 Apr 2025
    7.5
    High

    CVE-2025-27934

    Last Modified: 15 Apr 2026

    Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated attacker may obtain the product authentication information.

    Published: 9 Apr 2025
    9.8
    Critical

    CVE-2025-27797

    Last Modified: 15 Apr 2026

    OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.

    Published: 9 Apr 2025
    5.9
    Medium

    CVE-2025-27722

    Last Modified: 15 Apr 2026

    Cleartext transmission of sensitive information issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a man-in-the-middle attack may allow a remote unauthenticated attacker to eavesdrop the communication and obtain the authentication information.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-25213

    Last Modified: 15 Apr 2026

    Improper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the content on the malicious page while logged in, unintended operations may be performed.

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2025-25056

    Last Modified: 15 Apr 2026

    Cross-site request forgery vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views a malicious page while logged in, unintended operations may be performed.

    Published: 9 Apr 2025
    8.8
    High

    CVE-2025-25053

    Last Modified: 15 Apr 2026

    OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2025-23407

    Last Modified: 15 Apr 2026

    Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can log in to the product may alter the settings without appropriate privileges.

    Published: 9 Apr 2025
    5.5
    Medium

    CVE-2025-20952

    Last Modified: 2 Feb 2026

    Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.

    Published: 9 Apr 2025
    4.4
    Medium

    CVE-2025-3442

    Last Modified: 15 Apr 2026

    This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.

    Published: 9 Apr 2025
    6.3
    Medium

    CVE-2024-8243

    Last Modified: 22 Apr 2025

    The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2024-6860

    Last Modified: 22 Apr 2025

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack

    Published: 9 Apr 2025
    4.3
    Medium

    CVE-2024-6857

    Last Modified: 22 Apr 2025

    The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack

    Published: 9 Apr 2025
    6.4
    Medium

    CVE-2025-3100

    Last Modified: 21 Apr 2026

    The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 9 Apr 2025
    6.9
    Medium

    CVE-2025-29988

    Last Modified: 26 Feb 2026

    Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

    Published: 9 Apr 2025
    6.8
    Medium

    CVE-2025-32464

    Last Modified: 15 Apr 2026

    HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

    Published: 9 Apr 2025
    9.9
    Critical

    CVE-2025-32461

    Last Modified: 15 Apr 2026

    wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

    Published: 9 Apr 2025
    9.8
    Critical

    CVE-2024-55210

    Last Modified: 30 Apr 2025

    An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

    Published: 9 Apr 2025
    4.8
    Medium

    CVE-2025-29018

    Last Modified: 28 Apr 2025

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.

    Published: 9 Apr 2025
    4
    Medium

    CVE-2025-32460

    Last Modified: 29 Jan 2026

    GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

    Published: 9 Apr 2025
    8.1
    High

    CVE-2025-29394

    Last Modified: 15 Apr 2026

    An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.

    Published: 9 Apr 2025
    7.6
    High

    CVE-2025-29189

    Last Modified: 22 Apr 2025

    Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.

    Published: 9 Apr 2025
    6.1
    Medium

    CVE-2025-29389

    Last Modified: 15 Apr 2025

    PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.

    Published: 9 Apr 2025
    8.8
    High

    CVE-2025-29390

    Last Modified: 22 Apr 2025

    jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.

    Published: 9 Apr 2025
    7.2
    High

    CVE-2025-29391

    Last Modified: 22 Apr 2025

    horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.

    Published: 9 Apr 2025
    6.5
    Medium

    CVE-2025-25013

    Last Modified: 15 Apr 2026

    Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-27190

    Last Modified: 23 Jun 2025

    Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    5.3
    Medium

    CVE-2025-27191

    Last Modified: 20 May 2025

    Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    2.7
    Low

    CVE-2025-27192

    Last Modified: 20 May 2025

    Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2025-27188

    Last Modified: 1 May 2025

    Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    4.3
    Medium

    CVE-2025-27189

    Last Modified: 30 Apr 2025

    Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-22871

    Last Modified: 12 May 2026

    The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

    Published: 8 Apr 2025
    8.7
    High

    CVE-2024-12556

    Last Modified: 26 Feb 2026

    Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

    Published: 8 Apr 2025
    8.2
    High

    CVE-2025-30287

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

    Published: 8 Apr 2025
    6.8
    Medium

    CVE-2025-30293

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized write access. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 8 Apr 2025
    6.1
    Medium

    CVE-2025-30292

    Last Modified: 14 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

    Published: 8 Apr 2025
    8.7
    High

    CVE-2025-30290

    Last Modified: 12 May 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to bypass security protections and gain unauthorized write and delete access. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-30282

    Last Modified: 23 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 8 Apr 2025
    8.4
    High

    CVE-2025-30284

    Last Modified: 26 Feb 2026

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

    Published: 8 Apr 2025