CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2025-31526

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows SQL Injection.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2995

    Last Modified: 8 Apr 2025

    A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2994

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2993

    Last Modified: 8 Apr 2025

    A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    9.3
    Critical

    CVE-2025-3022

    Last Modified: 15 Apr 2026

    Os command injection vulnerability in e-solutions e-management. This vulnerability allows an attacker to execute arbitrary commands on the server via the ‘client’ parameter in the /data/apache/e-management/api/api3.php endpoint.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2992

    Last Modified: 7 Apr 2025

    A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    7.1
    High

    CVE-2025-23995

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through 1.0.0.5.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-31419

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeix Churel allows DOM-Based XSS.This issue affects Churel: from n/a through 1.0.8.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-30963

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows DOM-Based XSS.This issue affects JetSmartFilters: from n/a through <= 3.6.3.

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-3027

    Last Modified: 9 Oct 2025

    The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2991

    Last Modified: 7 Apr 2025

    A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-3026

    Last Modified: 9 Oct 2025

    The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect the client to a different base URL. In this way, an attacker could insert his own server for the client to send HTTP requests, provided he succeeds in exploiting it.

    Published: 31 Mar 2025
    8.7
    High

    CVE-2025-3021

    Last Modified: 15 Apr 2026

    Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confidential files outside the expected scope via the ‘file’ parameter in the /downloadReport.php endpoint.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2990

    Last Modified: 7 Apr 2025

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-31376

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Mayeenul Islam NanoSupport nanosupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through <= 0.6.0.

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31520

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31521

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31522

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31523

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31515

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31516

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31517

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31518

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-31519

    Last Modified: 1 Apr 2025

    Not used

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-31386

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in simplepress Simple:Press simplepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple:Press: from n/a through <= 6.11.5.

    Published: 31 Mar 2025
    6.9
    Medium

    CVE-2025-2989

    Last Modified: 7 Apr 2025

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-30961

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tinuzz Trackserver trackserver allows DOM-Based XSS.This issue affects Trackserver: from n/a through <= 5.1.0.

    Published: 31 Mar 2025
    —
    Unknown

    CVE-2025-3023

    Last Modified: 9 Apr 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-2985

    Last Modified: 14 May 2025

    A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. The manipulation of the argument deduction leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-31406

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ELEXtensions ELEX WooCommerce Request a Quote elex-request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WooCommerce Request a Quote: from n/a through <= 2.3.9.

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-2072

    Last Modified: 15 Apr 2026

    A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y".

    Published: 31 Mar 2025
    10
    Critical

    CVE-2025-2071

    Last Modified: 15 Apr 2026

    A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This vulnerability arises due to improper handling of untrusted input, which is passed directly to system-level commands without adequate sanitization or validation. Successful exploitation could allow attackers to execute arbitrary commands on the affected system, potentially resulting in unauthorized access, data leakage, or full system compromise. Affected WebUI parameters are "hd" and "pi".

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-2984

    Last Modified: 14 May 2025

    A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /delete.php. The manipulation of the argument emp_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-31410

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation wp-church-donation allows Cross Site Request Forgery.This issue affects WP Church Donation: from n/a through <= 1.7.

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-2983

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument redirect leads to os command injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-2586

    Last Modified: 25 Jun 2026

    A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability.

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-2982

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-2981

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, has been found in Legrand SMS PowerView 1.x. This issue affects some unknown processing. The manipulation of the argument redirect leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-3019

    Last Modified: 8 Oct 2025

    KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user clicks on a malicious link or opens a malicious web page, arbitrary Java Script may be executed with this user's permissions. This can lead to information loss and/or modification of existing data. The issues are caused by a bug https://github.com/Baroshem/nuxt-security/issues/610 in the widely used nuxt-security module. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.3 or later * 1.12.4 or later

    Published: 31 Mar 2025
    5.1
    Medium

    CVE-2025-2980

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in Legrand SMS PowerView 1.x. This vulnerability affects unknown code. The manipulation of the argument redirect leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Mar 2025
    8.8
    High

    CVE-2025-2402

    Last Modified: 8 Oct 2025

    A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-31414

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder allows Stored XSS.This issue affects Cost Calculator Builder: from n/a through <= 3.2.65.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-31412

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProductGallery jet-woo-product-gallery allows DOM-Based XSS.This issue affects JetProductGallery: from n/a through <= 2.1.22.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-31387

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect instawp-connect allows PHP Local File Inclusion.This issue affects InstaWP Connect: from n/a through <= 0.1.0.82.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-31016

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows PHP Local File Inclusion.This issue affects JetWooBuilder: from n/a through <= 2.1.18.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-30987

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.16.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-30855

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ads by WPQuads: from n/a through <= 2.0.87.1.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-30835

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Accounting for WooCommerce accounting-for-woocommerce allows PHP Local File Inclusion.This issue affects Accounting for WooCommerce: from n/a through <= 1.6.8.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-31417

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < 2.2.7.

    Published: 31 Mar 2025
    6.5
    Medium

    CVE-2025-31043

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.7.

    Published: 31 Mar 2025