CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-2047

    Last Modified: 3 Apr 2025

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    7.5
    High

    CVE-2025-27598

    Last Modified: 24 Mar 2025

    ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2046

    Last Modified: 29 Apr 2025

    A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.1
    Medium

    CVE-2025-2044

    Last Modified: 13 May 2025

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_bloodGroup.php. The manipulation of the argument blood_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.1
    Medium

    CVE-2025-2043

    Last Modified: 3 Oct 2025

    A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2042

    Last Modified: 15 Oct 2025

    A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2041

    Last Modified: 10 Oct 2025

    A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2040

    Last Modified: 7 Jul 2025

    A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.1
    Medium

    CVE-2025-2039

    Last Modified: 13 May 2025

    A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The manipulation of the argument member_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    6.9
    Medium

    CVE-2025-2038

    Last Modified: 13 May 2025

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    6.9
    Medium

    CVE-2025-27600

    Last Modified: 29 Dec 2025

    FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an intranet IP request, causing the system to initiate a request through the intranet and potentially obtain some private data on the intranet. This issue is fixed in 4.9.0.

    Published: 6 Mar 2025
    9.3
    Critical

    CVE-2025-27509

    Last Modified: 15 Apr 2026

    fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to forged assertions if f MDM enrollment is enabled. This vulnerability is fixed in 4.64.2, 4.63.2, 4.62.4, and 4.58.1.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2037

    Last Modified: 13 May 2025

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_dashboard/delete_requester.php. The manipulation of the argument requester_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.4
    Medium

    CVE-2025-27506

    Last Modified: 26 Aug 2025

    NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-Scripting. The flaw occurs due to implementation of the client-side template engine ejs, specifically on file resetPassword.ts where the template is using the insecure function “<%-“, which is rendered by the function renderPasswordReset. This vulnerability is fixed in 0.258.0.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-25294

    Last Modified: 4 Sept 2025

    Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This format is vulnerable to log injection attacks. If the attacker uses a specially crafted user-agent which performs json injection, then he could add and overwrite fields to the access log. This vulnerability is fixed in 1.3.1 and 1.2.7. One can overwrite the old text based default format with JSON formatter by modifying the "EnvoyProxy.spec.telemetry.accessLog" setting.

    Published: 6 Mar 2025
    6.9
    Medium

    CVE-2025-25191

    Last Modified: 10 Oct 2025

    Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitized before being stored. This vulnerability is fixed in 6.8.100.

    Published: 6 Mar 2025
    6.3
    Medium

    CVE-2025-24796

    Last Modified: 15 Apr 2026

    Collabora Online is a collaborative online office suite based on LibreOffice. Macro support is disabled by default in Collabora Online, but can be enabled by an administrator. Collabora Online typically hosts each document instance within a jail and is allowed to download content from locations controlled by the net.lok_allow configuration option, which by default include the private IP ranges to enable access to the local network. If enabled, macros were allowed run executable binaries. By combining an ability to host executables, typically in the local network, in an allowed accessible location, with a macro enabled Collabora Online, it was then possible to install arbitrary binaries within the jail and execute them. These executables are restricted to the same jail file system and user as the document instance but can be used to bypass the additional limits on what network hosts are accessible and provide more flexibility as a platform for further attempts. This is issue is fixed in 24.04.12.4, 23.05.19, 22.05.25 and later macros.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2036

    Last Modified: 10 Oct 2025

    A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2035

    Last Modified: 15 Oct 2025

    A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The manipulation of the argument name leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    6.9
    Medium

    CVE-2025-2034

    Last Modified: 7 May 2025

    A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php?cid=1. The manipulation of the argument classname/capacity/classtiming leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2033

    Last Modified: 13 May 2025

    A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /user_dashboard/view_donor.php. The manipulation of the argument donor_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    5.1
    Medium

    CVE-2025-2032

    Last Modified: 12 May 2025

    A vulnerability classified as problematic was found in ChestnutCMS 1.5.2. This vulnerability affects the function renameFile of the file /cms/file/rename. The manipulation of the argument rename leads to path traversal. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    7.1
    High

    CVE-2025-0337

    Last Modified: 15 Apr 2026

    ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable an authenticated user to access unauthorized data stored within the Now Platform that the user otherwise would not be entitled to access. This issue is addressed in the listed patches and family release, which have been made available to hosted and self-hosted customers, as well as partners.

    Published: 6 Mar 2025
    7.5
    High

    CVE-2024-51476

    Last Modified: 1 Sept 2025

    IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

    Published: 6 Mar 2025
    8.4
    High

    CVE-2024-12742

    Last Modified: 15 Apr 2026

    A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted project file.  This vulnerability affects G Web Development Software 2022 Q3 and prior versions.

    Published: 6 Mar 2025
    5.3
    Medium

    CVE-2025-2031

    Last Modified: 12 May 2025

    A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/upload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Mar 2025
    6.9
    Medium

    CVE-2025-2030

    Last Modified: 15 Apr 2026

    A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform up to 20250224. It has been rated as critical. Affected by this issue is some unknown functionality of the file /security/addUser.jsp. The manipulation of the argument groupId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Mar 2025
    4.8
    Medium

    CVE-2025-2029

    Last Modified: 15 Apr 2026

    A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. It has been classified as critical. Affected is an unknown function of the file mDicom.exe. The manipulation leads to memory corruption. The attack needs to be approached locally. It is recommended to upgrade the affected component. The vendor quickly confirmed the existence of the vulnerability and fixed it in the latest beta.

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27768

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27762

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27763

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27764

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27765

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27766

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27767

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27760

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    —
    Unknown

    CVE-2025-27761

    Last Modified: 17 Mar 2025

    Not used

    Published: 6 Mar 2025
    7.5
    High

    CVE-2024-12146

    Last Modified: 1 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (New System) allows SQL Injection. This issue affects Finder ERP/CRM (New System): before 18.12.2024.

    Published: 6 Mar 2025
    9.8
    Critical

    CVE-2024-12144

    Last Modified: 1 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection. This issue affects Finder ERP/CRM (Old System): before 18.12.2024.

    Published: 6 Mar 2025
    5.9
    Medium

    CVE-2024-13894

    Last Modified: 15 Apr 2026

    Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to path traversal. When an affected device is connected to a mobile app, it opens a port 10000 enabling a user to download pictures shot at specific moments by providing paths to the files. However, the directories to which a user has access are not limited, allowing for path traversal attacks and downloading sensitive information. The vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.

    Published: 6 Mar 2025
    7.5
    High

    CVE-2024-13893

    Last Modified: 15 Apr 2026

    Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory. For the telnet service to be enabled, the inserted SD card needs to have a folder with a specific name created.  Two products were tested, but since the vendor has not replied to reports, patching status remains unknown, as well as groups of devices and firmware ranges in which the same password is shared. Newer firmware versions might be vulnerable as well.

    Published: 6 Mar 2025
    7.7
    High

    CVE-2024-13892

    Last Modified: 15 Apr 2026

    Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. During the initialization process, a user has to use a mobile app to provide devices with Access Point credentials. This input is not properly sanitized, what allows for command injection. The vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.

    Published: 6 Mar 2025
    4.7
    Medium

    CVE-2025-0877

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS). This issue affects Reservation Management System: before 4.2.3.

    Published: 6 Mar 2025
    4.3
    Medium

    CVE-2025-2045

    Last Modified: 6 Aug 2025

    Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

    Published: 6 Mar 2025
    5.2
    Medium

    CVE-2025-1696

    Last Modified: 15 Apr 2026

    A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access. Starting with version 4.39.0, Docker Desktop no longer logs the proxy string, thereby mitigating this risk.

    Published: 6 Mar 2025
    6.3
    Medium

    CVE-2024-38311

    Last Modified: 29 Apr 2025

    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

    Published: 6 Mar 2025
    6.3
    Medium

    CVE-2024-56195

    Last Modified: 29 Apr 2025

    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the issue.

    Published: 6 Mar 2025
    6.3
    Medium

    CVE-2024-56196

    Last Modified: 7 May 2025

    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

    Published: 6 Mar 2025
    7.6
    High

    CVE-2024-7872

    Last Modified: 2 Jun 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data. This issue affects Extreme XDS: before 3933.

    Published: 6 Mar 2025
    4.3
    Medium

    CVE-2025-1666

    Last Modified: 20 Apr 2026

    The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit the uninstall survey on behalf of a website.

    Published: 6 Mar 2025