CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-10307

    Last Modified: 13 Aug 2025

    An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.

    Published: 28 Mar 2025
    5.2
    Medium

    CVE-2024-12619

    Last Modified: 13 Aug 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

    Published: 28 Mar 2025
    4.3
    Medium

    CVE-2025-1762

    Last Modified: 17 Apr 2025

    The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 28 Mar 2025
    5.9
    Medium

    CVE-2025-2027

    Last Modified: 15 Apr 2026

    A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service crash and potentially memory manipulation in some rare circumstances. Refer to the 'Security Update for MyASUS' section on the ASUS Security Advisory for more information.

    Published: 28 Mar 2025
    6.1
    Medium

    CVE-2025-2804

    Last Modified: 21 Apr 2026

    The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-2294

    Last Modified: 15 Apr 2026

    The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 28 Mar 2025
    6.6
    Medium

    CVE-2025-2894

    Last Modified: 12 Jan 2026

    The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

    Published: 28 Mar 2025
    8.8
    High

    CVE-2025-24381

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information. Exploitation may allow for session theft.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24386

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24377

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24378

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24379

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24380

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-23383

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2025-24385

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.

    Published: 28 Mar 2025
    7.3
    High

    CVE-2024-49601

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

    Published: 28 Mar 2025
    7.3
    High

    CVE-2025-24382

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-22398

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it can be leveraged to completely compromise the operating system. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2024-49563

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2024-49564

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.

    Published: 28 Mar 2025
    7.8
    High

    CVE-2024-49565

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

    Published: 28 Mar 2025
    9.1
    Critical

    CVE-2025-24383

    Last Modified: 26 Feb 2026

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 28 Mar 2025
    7.7
    High

    CVE-2025-1860

    Last Modified: 15 Apr 2026

    Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.

    Published: 28 Mar 2025
    4
    Medium

    CVE-2025-31335

    Last Modified: 15 Apr 2026

    The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

    Published: 28 Mar 2025
    7.5
    High

    CVE-2024-48615

    Last Modified: 14 Apr 2025

    Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-25579

    Last Modified: 7 Apr 2025

    TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-28219

    Last Modified: 2 May 2025

    Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

    Published: 28 Mar 2025
    7.5
    High

    CVE-2025-28221

    Last Modified: 8 May 2025

    Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2024-24292

    Last Modified: 17 Apr 2025

    A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2024-38985

    Last Modified: 30 Apr 2025

    janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2024-38988

    Last Modified: 14 Apr 2025

    alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2024-56975

    Last Modified: 14 Apr 2025

    InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

    Published: 28 Mar 2025
    7.5
    High

    CVE-2024-57083

    Last Modified: 14 Apr 2025

    A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

    Published: 28 Mar 2025
    5.5
    Medium

    CVE-2024-58128

    Last Modified: 8 Jul 2025

    In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.

    Published: 28 Mar 2025
    5.5
    Medium

    CVE-2024-58129

    Last Modified: 8 Jul 2025

    In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

    Published: 28 Mar 2025
    7.2
    High

    CVE-2024-58130

    Last Modified: 15 Jul 2025

    In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

    Published: 28 Mar 2025
    4.6
    Medium

    CVE-2025-2901

    Last Modified: 20 Jun 2025

    This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.

    Published: 28 Mar 2025
    6.3
    Medium

    CVE-2025-28092

    Last Modified: 7 Apr 2025

    ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

    Published: 28 Mar 2025
    6.3
    Medium

    CVE-2025-28093

    Last Modified: 7 Apr 2025

    ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

    Published: 28 Mar 2025
    6.5
    Medium

    CVE-2025-28094

    Last Modified: 7 Apr 2025

    shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

    Published: 28 Mar 2025
    5.4
    Medium

    CVE-2025-28096

    Last Modified: 7 Apr 2025

    OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

    Published: 28 Mar 2025
    5.5
    Medium

    CVE-2025-28097

    Last Modified: 7 Apr 2025

    OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-22953

    Last Modified: 15 Apr 2025

    A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features (like xp_cmdshell) are enabled, this may lead to remote code execution.

    Published: 28 Mar 2025
    9.1
    Critical

    CVE-2025-28091

    Last Modified: 7 Apr 2025

    maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-28087

    Last Modified: 7 Apr 2025

    Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.

    Published: 28 Mar 2025
    9.1
    Critical

    CVE-2025-28089

    Last Modified: 7 Apr 2025

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

    Published: 28 Mar 2025
    9.1
    Critical

    CVE-2025-28090

    Last Modified: 7 Apr 2025

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

    Published: 28 Mar 2025
    7.5
    High

    CVE-2025-28220

    Last Modified: 6 May 2025

    Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.

    Published: 28 Mar 2025
    5.4
    Medium

    CVE-2025-28254

    Last Modified: 7 Apr 2025

    Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().

    Published: 28 Mar 2025
    9.8
    Critical

    CVE-2025-28256

    Last Modified: 14 Apr 2025

    An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

    Published: 28 Mar 2025