CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2024-21760

    Last Modified: 24 Jul 2025

    An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2024-8997

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53.

    Published: 18 Mar 2025
    8.8
    High

    CVE-2025-2449

    Last Modified: 18 Aug 2025

    NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of URI files by the usiReg component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21805.

    Published: 18 Mar 2025
    8.8
    High

    CVE-2025-2450

    Last Modified: 18 Aug 2025

    NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of VBAI files. The issue results from allowing the execution of dangerous script without user warning. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22833.

    Published: 18 Mar 2025
    —
    Unknown

    CVE-2025-2496

    Last Modified: 26 Mar 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 18 Mar 2025
    5.3
    Medium

    CVE-2025-2495

    Last Modified: 21 Oct 2025

    Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript code injected via the ‘/softdial/scheduler/save.php’ resource. The injected code will execute when the uploaded file is loaded via the ‘/softdial/scheduler/load.php’ resource and can redirect the victim to malicious sites or steal their login information to spoof their identity.

    Published: 18 Mar 2025
    8.7
    High

    CVE-2025-2494

    Last Modified: 21 Oct 2025

    Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server.

    Published: 18 Mar 2025
    6.8
    Medium

    CVE-2025-2489

    Last Modified: 15 Apr 2026

    Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.

    Published: 18 Mar 2025
    8.7
    High

    CVE-2025-2493

    Last Modified: 21 Oct 2025

    Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to navigate beyond the intended directory. This can allow unauthorised access to sensitive files outside the expected scope, posing a security risk.

    Published: 18 Mar 2025
    5.3
    Medium

    CVE-2024-41975

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.

    Published: 18 Mar 2025
    6.6
    Medium

    CVE-2025-0694

    Last Modified: 15 Apr 2026

    Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.

    Published: 18 Mar 2025
    9.1
    Critical

    CVE-2024-23943

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices. Availability is not affected.

    Published: 18 Mar 2025
    7.1
    High

    CVE-2024-23942

    Last Modified: 15 Apr 2026

    A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-1468

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.

    Published: 18 Mar 2025
    8.4
    High

    CVE-2025-0755

    Last Modified: 3 Nov 2025

    The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16

    Published: 18 Mar 2025
    8.8
    High

    CVE-2025-25220

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker.

    Published: 18 Mar 2025
    7.2
    High

    CVE-2025-24306

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker with an administrative privilege.

    Published: 18 Mar 2025
    7.3
    High

    CVE-2025-2262

    Last Modified: 21 Apr 2026

    The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 18 Mar 2025
    6.9
    Medium

    CVE-2025-2473

    Last Modified: 21 May 2025

    A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Mar 2025
    4.9
    Medium

    CVE-2025-2487

    Last Modified: 30 Jun 2026

    A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

    Published: 18 Mar 2025
    8.8
    High

    CVE-2025-30106

    Last Modified: 15 Apr 2026

    On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi range to connect to the device's network to perform sniffing.

    Published: 18 Mar 2025
    8.1
    High

    CVE-2025-30142

    Last Modified: 1 Jul 2025

    An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for recognizing paired devices, allowing attackers to bypass authentication. By capturing the MAC address of an already-paired device through ARP scanning or other means, an attacker can spoof the MAC address and connect to the dashcam without going through the pairing process. This enables full access to the device.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-30140

    Last Modified: 1 Jul 2025

    An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a security risk. This domain was not owned by GNET originally, allowing an attacker to register it and potentially intercept sensitive device traffic (it has since been registered by the vulnerability discoverer). If the dashcam or related services attempt to resolve this domain over the public Internet instead of locally, it could lead to data exfiltration or man-in-the-middle attacks.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-30139

    Last Modified: 1 Jul 2025

    An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network without restriction. Once connected, an attacker can sniff on connected devices such as the user's smartphone. The SSID is also always broadcasted.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-30137

    Last Modified: 15 Apr 2026

    An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide unauthorized access to the dashcam's API endpoints on ports 9091 and 9092. Once the GNET SSID is connected to, the attacker sends a crafted authentication command with TibetList and 000000 to list settings of the dashcam at port 9091. There's a separate set of credentials for port 9092 (stream) that is also exposed in cleartext: admin + tibet. For settings, the required credentials are adim + 000000.

    Published: 18 Mar 2025
    6.8
    Medium

    CVE-2024-57151

    Last Modified: 1 Apr 2025

    SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

    Published: 18 Mar 2025
    6.5
    Medium

    CVE-2025-30110

    Last Modified: 15 Apr 2026

    On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, allowing an attacker to bypass authentication by spoofing an already-paired MAC address that can be captured via an ARP scan.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-30113

    Last Modified: 22 May 2025

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-30116

    Last Modified: 22 May 2025

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It allows remote attackers to access and download recorded video footage from the SD card via port 9091. Additionally, attackers can connect to port 9092 to stream the live video feed by bypassing the challenge-response authentication mechanism. This exposes sensitive location and personal data.

    Published: 18 Mar 2025
    4.6
    Medium

    CVE-2025-30138

    Last Modified: 1 Jul 2025

    An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons. It allows unauthorized users to modify critical system settings once connected to its network. Attackers can extract sensitive car and driver information, mute dashcam alerts to prevent detection, disable recording functionality, or even factory reset the device. Additionally, they can disable battery protection, causing the dashcam to drain the car battery when left on overnight. These actions not only compromise privacy but also pose potential physical harm by rendering the dashcam non-functional or causing vehicle battery failure.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-30141

    Last Modified: 1 Jul 2025

    An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints on ports 9091 and 9092 that allow remote access to recorded and live video feeds. An attacker who connects to the dashcam's network can retrieve all stored recordings and convert them from JDR format to MP4. Additionally, port 9092's RTSP stream can be accessed remotely, allowing real-time video feeds to be extracted without the owner's knowledge.

    Published: 18 Mar 2025
    8.1
    High

    CVE-2024-44313

    Last Modified: 2 Apr 2025

    TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.

    Published: 18 Mar 2025
    6.5
    Medium

    CVE-2024-44314

    Last Modified: 2 Apr 2025

    TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw can be exploited remotely, leading to unauthorized order manipulation.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2024-57169

    Last Modified: 2 Apr 2025

    A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.

    Published: 18 Mar 2025
    6.5
    Medium

    CVE-2024-57170

    Last Modified: 2 Apr 2025

    SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-25500

    Last Modified: 22 May 2025

    An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the blockchain.

    Published: 18 Mar 2025
    8.1
    High

    CVE-2025-25589

    Last Modified: 15 Apr 2026

    An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.

    Published: 18 Mar 2025
    6.1
    Medium

    CVE-2025-25580

    Last Modified: 19 Jun 2025

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.

    Published: 18 Mar 2025
    6.1
    Medium

    CVE-2025-25582

    Last Modified: 2 Apr 2025

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.

    Published: 18 Mar 2025
    7.3
    High

    CVE-2025-25585

    Last Modified: 19 Jun 2025

    Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

    Published: 18 Mar 2025
    4.2
    Medium

    CVE-2025-25586

    Last Modified: 1 Apr 2025

    yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.

    Published: 18 Mar 2025
    6.1
    Medium

    CVE-2025-25590

    Last Modified: 19 Jun 2025

    yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-25595

    Last Modified: 1 Apr 2025

    A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

    Published: 18 Mar 2025
    7.5
    High

    CVE-2025-26137

    Last Modified: 1 Apr 2025

    Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to read arbitrary system files by supplying a crafted file path, potentially exposing sensitive information.

    Published: 18 Mar 2025
    6.5
    Medium

    CVE-2025-26138

    Last Modified: 1 Apr 2025

    Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment or decrement the ID to access and download files they do not have permission to view.

    Published: 18 Mar 2025
    6.5
    Medium

    CVE-2025-30109

    Last Modified: 15 Apr 2026

    In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local Wi-Fi network to access API endpoints and retrieve sensitive device information, including live and recorded footage.

    Published: 18 Mar 2025
    9.1
    Critical

    CVE-2025-30114

    Last Modified: 22 May 2025

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scanning and spoofing it, an attacker can bypass the authentication process and gain full access to the dashcam's features without proper authorization.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-30115

    Last Modified: 22 May 2025

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It uses a fixed default SSID and password ("qwertyuiop"), which cannot be modified by users. The SSID is continuously broadcast, allowing unauthorized access to the device network.

    Published: 18 Mar 2025
    9.8
    Critical

    CVE-2025-30122

    Last Modified: 15 Apr 2026

    An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access to multiple devices.

    Published: 18 Mar 2025
    7.3
    High

    CVE-2025-30117

    Last Modified: 22 May 2025

    An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. After bypassing the device pairing, an attacker can obtain sensitive user and vehicle information through the settings interface. Remote attackers can modify power management settings, disable recording, delete stored footage, and turn off battery protection, leading to potential denial-of-service conditions and vehicle battery drainage.

    Published: 18 Mar 2025