CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-31727

    Last Modified: 17 Apr 2025

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

    Published: 2 Apr 2025
    5.5
    Medium

    CVE-2025-31726

    Last Modified: 18 Apr 2025

    Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 2 Apr 2025
    5.5
    Medium

    CVE-2025-31725

    Last Modified: 17 Apr 2025

    Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2025-31724

    Last Modified: 17 Apr 2025

    Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2025-31723

    Last Modified: 17 Apr 2025

    A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.

    Published: 2 Apr 2025
    8.8
    High

    CVE-2025-31722

    Last Modified: 26 Feb 2026

    In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2025-31721

    Last Modified: 29 Apr 2025

    A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2025-31720

    Last Modified: 29 Apr 2025

    A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.

    Published: 2 Apr 2025
    6.6
    Medium

    CVE-2024-25051

    Last Modified: 26 Feb 2026

    IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.

    Published: 2 Apr 2025
    8.5
    High

    CVE-2024-45064

    Last Modified: 5 Sept 2025

    A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 2 Apr 2025
    6.5
    Medium

    CVE-2024-50385

    Last Modified: 3 Nov 2025

    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

    Published: 2 Apr 2025
    6.5
    Medium

    CVE-2024-50384

    Last Modified: 3 Nov 2025

    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2024-50595

    Last Modified: 3 Nov 2025

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2024-50594

    Last Modified: 3 Nov 2025

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2024-50597

    Last Modified: 3 Nov 2025

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c

    Published: 2 Apr 2025
    4.3
    Medium

    CVE-2024-50596

    Last Modified: 3 Nov 2025

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c

    Published: 2 Apr 2025
    5.3
    Medium

    CVE-2025-1805

    Last Modified: 15 Apr 2026

    Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.

    Published: 2 Apr 2025
    6.1
    Medium

    CVE-2025-3097

    Last Modified: 20 Apr 2026

    The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the 'wpTimeMachineCore.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 2 Apr 2025
    8.8
    High

    CVE-2025-3063

    Last Modified: 15 Apr 2026

    The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_callback_update_sa_option() function in versions 2.0 to 2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 2 Apr 2025
    6.1
    Medium

    CVE-2025-2483

    Last Modified: 20 Apr 2026

    The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_address’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 2 Apr 2025
    6.5
    Medium

    CVE-2024-13637

    Last Modified: 15 Apr 2026

    The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin function in all versions up to, and including, 1.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins..

    Published: 2 Apr 2025
    4.9
    Medium

    CVE-2024-12410

    Last Modified: 8 Apr 2026

    The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 2 Apr 2025
    6.4
    Medium

    CVE-2025-2513

    Last Modified: 21 Apr 2026

    The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 2 Apr 2025
    6.1
    Medium

    CVE-2025-3098

    Last Modified: 22 Apr 2026

    The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.0.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 2 Apr 2025
    6.1
    Medium

    CVE-2025-3099

    Last Modified: 22 Apr 2026

    The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the 'MySolrServerSettings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 2 Apr 2025
    9.8
    Critical

    CVE-2025-2005

    Last Modified: 22 Apr 2026

    The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 2 Apr 2025
    9.9
    Critical

    CVE-2023-40714

    Last Modified: 15 Jul 2025

    A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements

    Published: 2 Apr 2025
    7.8
    High

    CVE-2024-39780

    Last Modified: 26 Aug 2025

    A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code.

    Published: 2 Apr 2025
    8.6
    High

    CVE-2025-0676

    Last Modified: 15 Apr 2026

    This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell access and maintain persistent control over the device, potentially disrupting network services and affecting the availability of downstream systems that rely on its connectivity.

    Published: 2 Apr 2025
    9.2
    Critical

    CVE-2025-0415

    Last Modified: 15 Apr 2026

    A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

    Published: 2 Apr 2025
    6
    Medium

    CVE-2024-45700

    Last Modified: 3 Nov 2025

    Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.

    Published: 2 Apr 2025
    7.5
    High

    CVE-2024-45699

    Last Modified: 3 Nov 2025

    The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

    Published: 2 Apr 2025
    2.1
    Low

    CVE-2024-42325

    Last Modified: 3 Nov 2025

    Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.

    Published: 2 Apr 2025
    2.3
    Low

    CVE-2024-36469

    Last Modified: 3 Nov 2025

    Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.

    Published: 2 Apr 2025
    8.6
    High

    CVE-2024-36465

    Last Modified: 8 Oct 2025

    A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

    Published: 2 Apr 2025
    5.9
    Medium

    CVE-2025-27244

    Last Modified: 15 Apr 2026

    AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If exploited, sensitive information may be obtained by a remote unauthenticated attacker.

    Published: 2 Apr 2025
    8.2
    High

    CVE-2025-25060

    Last Modified: 15 Apr 2026

    Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is running may be obtained and/or deleted by a remote unauthenticated attacker.

    Published: 2 Apr 2025
    6.5
    Medium

    CVE-2025-2779

    Last Modified: 22 Apr 2026

    The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.

    Published: 2 Apr 2025
    5.4
    Medium

    CVE-2025-3074

    Last Modified: 21 Apr 2025

    Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Apr 2025
    5.4
    Medium

    CVE-2025-3073

    Last Modified: 21 Apr 2025

    Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Apr 2025
    5.4
    Medium

    CVE-2025-3072

    Last Modified: 21 Apr 2025

    Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Apr 2025
    5.4
    Medium

    CVE-2025-3071

    Last Modified: 21 Apr 2025

    Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Apr 2025
    6.5
    Medium

    CVE-2025-3070

    Last Modified: 7 Apr 2025

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Apr 2025
    8.8
    High

    CVE-2025-3069

    Last Modified: 26 Feb 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Apr 2025
    8.8
    High

    CVE-2025-3068

    Last Modified: 26 Feb 2026

    Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Apr 2025
    8.6
    High

    CVE-2025-3067

    Last Modified: 26 Feb 2026

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)

    Published: 2 Apr 2025
    8.8
    High

    CVE-2025-3066

    Last Modified: 26 Feb 2026

    Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Apr 2025
    4.7
    Medium

    CVE-2025-27692

    Last Modified: 11 Jul 2025

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution

    Published: 2 Apr 2025
    4.9
    Medium

    CVE-2025-27693

    Last Modified: 11 Jul 2025

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

    Published: 2 Apr 2025
    5.3
    Medium

    CVE-2025-27694

    Last Modified: 11 Jul 2025

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

    Published: 2 Apr 2025