CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-2368

    Last Modified: 6 Jan 2026

    A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2367

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formScript of the component Personal Script Submenu. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    4.8
    Medium

    CVE-2025-2366

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add Department Page. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    7.4
    High

    CVE-2025-1724

    Last Modified: 15 Apr 2026

    Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2365

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Mar 2025
    5.1
    Medium

    CVE-2025-2364

    Last Modified: 14 Oct 2025

    A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the argument mdContent/htmlContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    8.8
    High

    CVE-2025-2396

    Last Modified: 18 Nov 2025

    The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published: 17 Mar 2025
    9.8
    Critical

    CVE-2025-2395

    Last Modified: 18 Nov 2025

    The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2363

    Last Modified: 14 Oct 2025

    A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    8.6
    High

    CVE-2024-12992

    Last Modified: 16 Sept 2025

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .

    Published: 17 Mar 2025
    8.6
    High

    CVE-2024-12971

    Last Modified: 16 Sept 2025

    Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

    Published: 17 Mar 2025
    6.9
    Medium

    CVE-2025-2362

    Last Modified: 6 May 2025

    A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2361

    Last Modified: 15 Apr 2026

    A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    6.9
    Medium

    CVE-2025-2360

    Last Modified: 15 Jul 2025

    A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 17 Mar 2025
    6.9
    Medium

    CVE-2025-2359

    Last Modified: 15 Jul 2025

    A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2358

    Last Modified: 15 Apr 2026

    A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Kfxt/Service.asmx of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2357

    Last Modified: 3 Nov 2025

    A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The manipulation leads to memory corruption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 3239a7915. It is recommended to apply a patch to fix this issue.

    Published: 17 Mar 2025
    6.3
    Medium

    CVE-2025-2356

    Last Modified: 15 Apr 2026

    A vulnerability was found in BlackVue App 3.65 on Android. It has been classified as problematic. This affects the function deviceDelete of the component API Handler. The manipulation leads to use of get request method with sensitive query strings. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    4.8
    Medium

    CVE-2025-2355

    Last Modified: 15 Apr 2026

    A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic. Affected by this issue is some unknown functionality of the component API Endpoint Handler. The manipulation of the argument BCS_TOKEN/SECRET_KEY leads to unprotected storage of credentials. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    5.3
    Medium

    CVE-2025-2354

    Last Modified: 15 Apr 2026

    A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vam/index.php. The manipulation of the argument registry_id/plane_icao/hub_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Mar 2025
    9.1
    Critical

    CVE-2025-25650

    Last Modified: 15 Apr 2026

    An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.

    Published: 17 Mar 2025
    7.1
    High

    CVE-2025-25612

    Last Modified: 15 Apr 2026

    FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.

    Published: 17 Mar 2025
    3.2
    Low

    CVE-2025-29431

    Last Modified: 2 Apr 2025

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.

    Published: 17 Mar 2025
    6.1
    Medium

    CVE-2025-29429

    Last Modified: 23 Oct 2025

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.

    Published: 17 Mar 2025
    5.5
    Medium

    CVE-2025-29425

    Last Modified: 23 Oct 2025

    Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.

    Published: 17 Mar 2025
    3.3
    Low

    CVE-2025-25618

    Last Modified: 24 Jun 2025

    Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.

    Published: 17 Mar 2025
    7.5
    High

    CVE-2025-25685

    Last Modified: 15 Apr 2026

    An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.

    Published: 17 Mar 2025
    4.6
    Medium

    CVE-2025-29426

    Last Modified: 2 Apr 2025

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and cys parameters.

    Published: 17 Mar 2025
    5.9
    Medium

    CVE-2025-29427

    Last Modified: 23 Oct 2025

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.

    Published: 17 Mar 2025
    4.1
    Medium

    CVE-2025-29430

    Last Modified: 23 Oct 2025

    Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.

    Published: 17 Mar 2025
    6
    Medium

    CVE-2025-26042

    Last Modified: 15 Apr 2026

    Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.

    Published: 17 Mar 2025
    6.8
    Medium

    CVE-2024-44866

    Last Modified: 15 Apr 2026

    A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.

    Published: 17 Mar 2025
    4.3
    Medium

    CVE-2025-25621

    Last Modified: 24 Jun 2025

    Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.

    Published: 17 Mar 2025
    7.5
    High

    CVE-2025-25684

    Last Modified: 15 Apr 2026

    A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the device's file system via a crafted POST request.

    Published: 17 Mar 2025
    9.8
    Critical

    CVE-2025-25914

    Last Modified: 8 Apr 2025

    SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter

    Published: 17 Mar 2025
    7.3
    High

    CVE-2025-26125

    Last Modified: 15 Apr 2026

    An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

    Published: 17 Mar 2025
    5
    Medium

    CVE-2025-26127

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 17 Mar 2025
    5.4
    Medium

    CVE-2025-30143

    Last Modified: 15 Apr 2026

    Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.

    Published: 17 Mar 2025
    6.9
    Medium

    CVE-2025-2353

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument ID/registry_id/plane_icao leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    4.8
    Medium

    CVE-2025-2352

    Last Modified: 10 Oct 2025

    A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of the component Backend. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    6.9
    Medium

    CVE-2025-2351

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    5.3
    Medium

    CVE-2025-2350

    Last Modified: 6 Nov 2025

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality of the file /action/upload_file. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.

    Published: 16 Mar 2025
    2.3
    Low

    CVE-2025-2349

    Last Modified: 6 Nov 2025

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/passwd of the component Password Hash Handler. The manipulation leads to password hash with insufficient computational effort. Access to the local network is required for this attack. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 16 Mar 2025
    5.3
    Medium

    CVE-2025-2348

    Last Modified: 6 Nov 2025

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /mnt/extsd/event/ of the component HTTP/RTSP. The manipulation leads to information disclosure. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

    Published: 16 Mar 2025
    5.3
    Medium

    CVE-2025-2347

    Last Modified: 4 Nov 2025

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The manipulation of the argument Password with the input qwertyuiop leads to use of default password. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.

    Published: 16 Mar 2025
    6.3
    Medium

    CVE-2025-2346

    Last Modified: 15 Apr 2026

    A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. The manipulation of the argument Domain Name leads to origin validation error. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.

    Published: 16 Mar 2025
    9.3
    Critical

    CVE-2025-2345

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    6.9
    Medium

    CVE-2025-2344

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    7.7
    High

    CVE-2025-2343

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an unknown functionality of the component Device Pairing. The manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The complexity of an attack is rather high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025
    6.9
    Medium

    CVE-2025-2342

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2025