CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2025-27018

    Last Modified: 3 Jun 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

    Published: 19 Mar 2025
    6.9
    Medium

    CVE-2024-12136

    Last Modified: 1 Jun 2026

    Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass. This issue affects ANKA JPD-00028: before V.01.01.

    Published: 19 Mar 2025
    7.6
    High

    CVE-2024-12137

    Last Modified: 1 Jun 2026

    Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. This issue affects ANKA JPD-00028: before V.01.01.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-13790

    Last Modified: 15 Apr 2026

    The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 19 Mar 2025
    7.5
    High

    CVE-2024-13412

    Last Modified: 15 Apr 2026

    The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to execute arbitrary actions.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-13410

    Last Modified: 15 Apr 2026

    The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versions up to, and including 3.9.0, respectively, via deserialization of untrusted input in the 'ajax_handler' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 19 Mar 2025
    8.8
    High

    CVE-2025-1232

    Last Modified: 9 May 2025

    The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks

    Published: 19 Mar 2025
    7.5
    High

    CVE-2024-50631

    Last Modified: 16 Jan 2026

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors.

    Published: 19 Mar 2025
    7.5
    High

    CVE-2024-50630

    Last Modified: 16 Jan 2026

    Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.

    Published: 19 Mar 2025
    5.3
    Medium

    CVE-2024-50629

    Last Modified: 17 Nov 2025

    Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-12922

    Last Modified: 15 Apr 2026

    The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 19 Mar 2025
    8.8
    High

    CVE-2024-12295

    Last Modified: 15 Apr 2026

    The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the 'boombox_ajax_reset_password' function. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

    Published: 19 Mar 2025
    5.3
    Medium

    CVE-2025-2290

    Last Modified: 21 Apr 2026

    The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated attackers to change status to "Trash" for every published post, therefore limiting the availability of the website's content.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-11131

    Last Modified: 16 Jan 2026

    A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.

    Published: 19 Mar 2025
    10
    Critical

    CVE-2024-10442

    Last Modified: 16 Jan 2026

    Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.

    Published: 19 Mar 2025
    4.3
    Medium

    CVE-2024-10445

    Last Modified: 17 Nov 2025

    Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-10441

    Last Modified: 17 Nov 2025

    Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 Mar 2025
    7.5
    High

    CVE-2024-10444

    Last Modified: 17 Nov 2025

    Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 19 Mar 2025
    8.6
    High

    CVE-2025-30236

    Last Modified: 15 Apr 2026

    Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSION parameter.

    Published: 19 Mar 2025
    3.5
    Low

    CVE-2025-30259

    Last Modified: 15 Apr 2026

    The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL.

    Published: 19 Mar 2025
    2.7
    Low

    CVE-2025-30258

    Last Modified: 16 Oct 2025

    In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

    Published: 19 Mar 2025
    8.3
    High

    CVE-2025-30234

    Last Modified: 15 Apr 2026

    SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26).

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2025-29137

    Last Modified: 1 Apr 2025

    Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.

    Published: 19 Mar 2025
    3.5
    Low

    CVE-2025-30235

    Last Modified: 15 Apr 2026

    Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 is intended to disable accounts that have had more than 10 failed authentication attempts, but instead allows hundreds of failed authentication attempts, because concurrent attempts are mishandled.

    Published: 19 Mar 2025
    6.1
    Medium

    CVE-2024-55009

    Last Modified: 24 Mar 2025

    A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.

    Published: 19 Mar 2025
    8.3
    High

    CVE-2024-55551

    Last Modified: 26 Sept 2025

    An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2024-57061

    Last Modified: 15 Apr 2026

    An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

    Published: 19 Mar 2025
    6.5
    Medium

    CVE-2025-26816

    Last Modified: 15 Apr 2026

    A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context.

    Published: 19 Mar 2025
    6.5
    Medium

    CVE-2025-29118

    Last Modified: 1 Apr 2025

    Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

    Published: 19 Mar 2025
    9.8
    Critical

    CVE-2025-29401

    Last Modified: 16 Jun 2025

    An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 19 Mar 2025
    6.3
    Medium

    CVE-2025-29405

    Last Modified: 12 Jun 2025

    An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 19 Mar 2025
    6.1
    Medium

    CVE-2025-30092

    Last Modified: 15 Apr 2026

    Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.

    Published: 19 Mar 2025
    8.8
    High

    CVE-2024-12563

    Last Modified: 15 Apr 2026

    The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution.

    Published: 18 Mar 2025
    6
    Medium

    CVE-2025-27080

    Last Modified: 15 Apr 2026

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to lateral movement involving those services.

    Published: 18 Mar 2025
    4.3
    Medium

    CVE-2025-25042

    Last Modified: 15 Apr 2026

    A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.

    Published: 18 Mar 2025
    3.3
    Low

    CVE-2025-25040

    Last Modified: 22 Sept 2026

    A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.

    Published: 18 Mar 2025
    6.9
    Medium

    CVE-2025-29930

    Last Modified: 15 Apr 2026

    imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g., seoOp=php://filter/read=convert.base64-encode/resource=/var/www/html/config.php), the application could allow an attacker to read sensitive files on the server (Local File Inclusion, LFI). The $_GET['seoOp'] and $_GET['seoArg'] parameters are directly used without sanitization or validation. This is partly mitigated by the fact that the ImpressCMS sensitive files are stored outside the web root, in a folder with a randomized name. The issue has been resolved in imFaq 1.0.1.

    Published: 18 Mar 2025
    8.7
    High

    CVE-2025-29907

    Last Modified: 22 Sept 2025

    jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the addImage method, a user can provide a harmful data-url that results in high CPU utilization and denial of service. Other affected methods are html and addSvgAsImage. The vulnerability was fixed in jsPDF 3.0.1.

    Published: 18 Mar 2025
    4.8
    Medium

    CVE-2025-29790

    Last Modified: 4 Nov 2025

    Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.

    Published: 18 Mar 2025
    8.5
    High

    CVE-2025-24801

    Last Modified: 1 Aug 2025

    GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-24799

    Last Modified: 31 Jul 2025

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

    Published: 18 Mar 2025
    8.2
    High

    CVE-2025-21619

    Last Modified: 31 Jul 2025

    GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

    Published: 18 Mar 2025
    —
    Unknown

    CVE-2025-2504

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 18 Mar 2025
    9.6
    Critical

    CVE-2024-56347

    Last Modified: 26 Feb 2026

    IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

    Published: 18 Mar 2025
    10
    Critical

    CVE-2024-56346

    Last Modified: 26 Feb 2026

    IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

    Published: 18 Mar 2025
    7.8
    High

    CVE-2025-27688

    Last Modified: 26 Feb 2026

    Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 18 Mar 2025
    4.8
    Medium

    CVE-2025-2491

    Last Modified: 4 Nov 2025

    A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Mar 2025
    4.1
    Medium

    CVE-2024-49822

    Last Modified: 1 Sept 2025

    IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 18 Mar 2025
    4.8
    Medium

    CVE-2025-2490

    Last Modified: 6 Nov 2025

    A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2023-47539

    Last Modified: 26 Feb 2026

    An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.

    Published: 18 Mar 2025