CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-30742

    Last Modified: 15 Apr 2026

    httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.

    Published: 26 Mar 2025
    6.5
    Medium

    CVE-2024-55963

    Last Modified: 1 Apr 2025

    An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.

    Published: 26 Mar 2025
    7.5
    High

    CVE-2025-26001

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.

    Published: 26 Mar 2025
    7.5
    High

    CVE-2025-26009

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

    Published: 26 Mar 2025
    6.8
    Medium

    CVE-2024-41643

    Last Modified: 15 Apr 2026

    An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2024-55964

    Last Modified: 1 Apr 2025

    An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.

    Published: 26 Mar 2025
    6.5
    Medium

    CVE-2024-55965

    Last Modified: 8 Jul 2025

    An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, such as database passwords and API Keys.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-25535

    Last Modified: 15 Apr 2026

    HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26002

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26003

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26004

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26005

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26006

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26007

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26008

    Last Modified: 1 Apr 2025

    In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26010

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.

    Published: 26 Mar 2025
    9.8
    Critical

    CVE-2025-26011

    Last Modified: 1 Apr 2025

    Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.

    Published: 26 Mar 2025
    7.5
    High

    CVE-2025-28361

    Last Modified: 1 Apr 2025

    Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.

    Published: 26 Mar 2025
    4.6
    Medium

    CVE-2025-29322

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary code via a crafted payload to the "Connection Name" in the New Connection and Rename Connection pages.

    Published: 26 Mar 2025
    4.3
    Medium

    CVE-2025-2276

    Last Modified: 20 Apr 2026

    The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_module_actions function in all versions up to, and including, 3.8.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate/deactivate plugin modules.

    Published: 25 Mar 2025
    6.4
    Medium

    CVE-2025-2302

    Last Modified: 20 Apr 2026

    The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_terms shortcode in all versions up to, and including, 3.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Mar 2025
    9.8
    Critical

    CVE-2024-47516

    Last Modified: 15 Apr 2026

    A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

    Published: 25 Mar 2025
    2.1
    Low

    CVE-2025-30222

    Last Modified: 15 Apr 2026

    Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential environment variable exposure on Windows with CMD. This impact users of Shescape on Windows that explicitly configure `shell: 'cmd.exe'` or `shell: true` using any of `quote`/`quoteAll`/`escape`/`escapeAll`. An attacker may be able to get read-only access to environment variables. This bug has been patched in v2.1.2. For those who are already using v2 of Shescape, no further changes are required. Those who are are using v1 of Shescape should follow the migration guide to upgrade to v2. There is no plan to release a patch compatible with v1 of Shescape. As a workaround, users can remove all instances of `%` from user input before using Shescape.

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2025-30219

    Last Modified: 15 Apr 2026

    RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails to start, recent versions will display an error message (a notification) in the management UI. The error message includes virtual host name, which was not escaped prior to open source RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3, 3.13.8. An attack that both makes a virtual host fail to start and creates a new virtual host name with an XSS code snippet or changes the name of an existing virtual host on disk could trigger arbitrary JavaScript code execution in the management UI (the user's browser). Open source RabbitMQ `4.0.3` and Tanzu RabbitMQ `4.0.3` and `3.13.8` patch the issue.

    Published: 25 Mar 2025
    4.6
    Medium

    CVE-2025-29789

    Last Modified: 6 May 2025

    OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.

    Published: 25 Mar 2025
    9.4
    Critical

    CVE-2025-30216

    Last Modified: 6 May 2025

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow vulnerability occurs in the `Crypto_TM_ProcessSecurity` function (`crypto_tm.c:1735:8`). When processing the Secondary Header Length of a TM protocol packet, if the Secondary Header Length exceeds the packet's total length, a heap overflow is triggered during the memcpy operation that copies packet data into the dynamically allocated buffer `p_new_dec_frame`. This allows an attacker to overwrite adjacent heap memory, potentially leading to arbitrary code execution or system instability. A patch is available at commit 810fd66d592c883125272fef123c3240db2f170f.

    Published: 25 Mar 2025
    5.9
    Medium

    CVE-2024-31896

    Last Modified: 1 Sept 2025

    IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

    Published: 25 Mar 2025
    7.5
    High

    CVE-2025-30567

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

    Published: 25 Mar 2025
    9.3
    Critical

    CVE-2025-28904

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free allows Blind SQL Injection.This issue affects Web Directory Free: from n/a through <= 1.7.6.

    Published: 25 Mar 2025
    7.3
    High

    CVE-2024-58105

    Last Modified: 26 Feb 2026

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 Mar 2025
    7.3
    High

    CVE-2024-58104

    Last Modified: 26 Feb 2026

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 Mar 2025
    —
    Unknown

    CVE-2025-2795

    Last Modified: 21 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 Mar 2025
    8
    High

    CVE-2025-30214

    Last Modified: 1 Aug 2025

    Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. There's no workaround to fix this without upgrading.

    Published: 25 Mar 2025
    6.3
    Medium

    CVE-2025-30213

    Last Modified: 1 Aug 2025

    Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code execution. Versions 14.9.1 and 15.52.0 contain a patch for the vulnerability. There's no workaround; an upgrade is required.

    Published: 25 Mar 2025
    6.5
    Medium

    CVE-2025-26742

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35.

    Published: 25 Mar 2025
    8.2
    High

    CVE-2025-27147

    Last Modified: 15 Apr 2026

    The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data collection (files, Windows registry, WMI). Versions prior to 1.5.0 have an improper access control vulnerability. Version 1.5.0 fixes the vulnerability.

    Published: 25 Mar 2025
    6.6
    Medium

    CVE-2025-30212

    Last Modified: 1 Aug 2025

    Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to access sensitive information. Versions 14.89.0 and 15.51.0 fix the issue. Upgrading is required; no other workaround is present.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-2532

    Last Modified: 5 Sept 2025

    Luxion KeyShot USDC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of usdc files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23709.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-2531

    Last Modified: 11 Aug 2025

    Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of dae files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23704.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-2530

    Last Modified: 11 Aug 2025

    Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of dae files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23698.

    Published: 25 Mar 2025
    4.8
    Medium

    CVE-2024-55604

    Last Modified: 24 Oct 2025

    Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not have access to development information of a workspace. Datasources are such a component in a workspace. Yet, in versions of Appsmith prior to 1.51, app viewers are able to get a list of datasources in a workspace they're a member of. This information disclosure does NOT expose sensitive data in the datasources, such as database passwords and API Keys. The attacker needs to have been invited to a workspace as a "viewer", by someone in that workspace with access to invite. The attacker then needs to be able to signup/login to that Appsmith instance. The issue is patched in version 1.51. No known workarounds are available.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-22230

    Last Modified: 15 Apr 2026

    VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gain ability to perform certain high privilege operations within that VM.

    Published: 25 Mar 2025
    6.5
    Medium

    CVE-2025-27631

    Last Modified: 15 Apr 2026

    The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.

    Published: 25 Mar 2025
    4.1
    Medium

    CVE-2025-29932

    Last Modified: 30 Sept 2025

    In JetBrains GoLand before 2025.1 an XXE during debugging was possible

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2025-27633

    Last Modified: 15 Apr 2026

    The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality and integrity of the system.

    Published: 25 Mar 2025
    8.7
    High

    CVE-2025-1445

    Last Modified: 15 Apr 2026

    A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on RTU500 device. It affects the CMU the IEC61850 stack is configured on.

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2025-27632

    Last Modified: 15 Apr 2026

    A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.

    Published: 25 Mar 2025
    8.7
    High

    CVE-2024-12169

    Last Modified: 15 Apr 2026

    A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3 (TLS) is enabled.

    Published: 25 Mar 2025
    6.9
    Medium

    CVE-2024-11499

    Last Modified: 15 Apr 2026

    A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.

    Published: 25 Mar 2025
    5.5
    Medium

    CVE-2022-1804

    Last Modified: 26 Aug 2025

    accountsservice no longer drops permissions when writting .pam_environment

    Published: 25 Mar 2025