CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-8314

    Last Modified: 15 Apr 2026

    An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

    Published: 25 Mar 2025
    8.7
    High

    CVE-2024-8313

    Last Modified: 15 Apr 2026

    An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2732

    Last Modified: 15 Apr 2026

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2731

    Last Modified: 15 Apr 2026

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2730

    Last Modified: 15 Apr 2026

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2729

    Last Modified: 15 Apr 2026

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2728

    Last Modified: 15 Apr 2026

    A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2727

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    7.1
    High

    CVE-2024-13863

    Last Modified: 29 Apr 2025

    The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 25 Mar 2025
    7.2
    High

    CVE-2024-13618

    Last Modified: 20 Jun 2025

    The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

    Published: 25 Mar 2025
    8.6
    High

    CVE-2024-13617

    Last Modified: 20 Jun 2025

    The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

    Published: 25 Mar 2025
    3.5
    Low

    CVE-2024-13123

    Last Modified: 1 Apr 2025

    The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    3.5
    Low

    CVE-2024-13122

    Last Modified: 1 Apr 2025

    The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    4.3
    Medium

    CVE-2024-13118

    Last Modified: 6 May 2025

    The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack

    Published: 25 Mar 2025
    3.5
    Low

    CVE-2024-12769

    Last Modified: 29 Apr 2025

    The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2726

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-12682

    Last Modified: 6 May 2025

    The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    4.1
    Medium

    CVE-2024-12109

    Last Modified: 29 Apr 2025

    The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-11503

    Last Modified: 29 Apr 2025

    The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-11273

    Last Modified: 15 May 2025

    The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-11272

    Last Modified: 15 May 2025

    The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    8.6
    High

    CVE-2025-2725

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-10703

    Last Modified: 15 May 2025

    The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-10679

    Last Modified: 6 May 2025

    The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    4.1
    Medium

    CVE-2024-10638

    Last Modified: 5 May 2025

    The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-10566

    Last Modified: 1 Apr 2025

    The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    6.1
    Medium

    CVE-2024-10565

    Last Modified: 2 Apr 2025

    The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    3.5
    Low

    CVE-2024-10560

    Last Modified: 3 Apr 2025

    The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    3.5
    Low

    CVE-2024-10554

    Last Modified: 15 May 2025

    The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    5.9
    Medium

    CVE-2024-10472

    Last Modified: 15 May 2025

    The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    5.9
    Medium

    CVE-2024-10105

    Last Modified: 2 Apr 2025

    The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 25 Mar 2025
    3.3
    Low

    CVE-2025-2724

    Last Modified: 22 Apr 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "the only way to get an object of type GsfMSOleSortingKey is via gsf_msole_sorting_key_new which adds that extra zero element".

    Published: 25 Mar 2025
    5.3
    Medium

    CVE-2025-2723

    Last Modified: 22 Apr 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [as] the buffer pointed to by "data" must have "len" valid bytes." The documentation was fixed to make that clear.

    Published: 25 Mar 2025
    —
    Unknown

    CVE-2025-2722

    Last Modified: 22 Apr 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [because] p_n_param is an input-output parameter indicating how big an array has already been allocated.

    Published: 25 Mar 2025
    —
    Unknown

    CVE-2025-2721

    Last Modified: 22 Apr 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [as] the buffer pointed to by "data" must have "len" valid bytes." The documentation was fixed to make that clear.

    Published: 25 Mar 2025
    7
    High

    CVE-2025-2784

    Last Modified: 30 Jun 2026

    A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.

    Published: 25 Mar 2025
    9.8
    Critical

    CVE-2025-27837

    Last Modified: 23 Jun 2026

    An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

    Published: 25 Mar 2025
    7.2
    High

    CVE-2025-29635

    Last Modified: 22 Aug 2026

    A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

    Published: 25 Mar 2025
    9.4
    Critical

    CVE-2025-30091

    Last Modified: 15 Apr 2026

    In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.

    Published: 25 Mar 2025
    4.3
    Medium

    CVE-2025-2786

    Last Modified: 15 Apr 2026

    A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.

    Published: 25 Mar 2025
    9.8
    Critical

    CVE-2024-48818

    Last Modified: 15 Apr 2026

    An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.

    Published: 25 Mar 2025
    9.8
    Critical

    CVE-2024-42533

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.

    Published: 25 Mar 2025
    6.5
    Medium

    CVE-2025-2877

    Last Modified: 15 Apr 2026

    A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams.

    Published: 25 Mar 2025
    8.3
    High

    CVE-2025-2783

    Last Modified: 26 Feb 2026

    Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

    Published: 25 Mar 2025
    4.3
    Medium

    CVE-2025-30741

    Last Modified: 15 Apr 2026

    Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-27835

    Last Modified: 3 Nov 2025

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

    Published: 25 Mar 2025
    9.8
    Critical

    CVE-2025-27831

    Last Modified: 3 Nov 2025

    An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-27834

    Last Modified: 1 Apr 2025

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-27833

    Last Modified: 1 Apr 2025

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

    Published: 25 Mar 2025
    7.8
    High

    CVE-2025-27830

    Last Modified: 3 Nov 2025

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

    Published: 25 Mar 2025