CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-27681

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004.

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-27683

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.

    Published: 5 Mar 2025
    7.5
    High

    CVE-2025-27685

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

    Published: 5 Mar 2025
    7.2
    High

    CVE-2024-31525

    Last Modified: 15 Apr 2026

    Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.

    Published: 5 Mar 2025
    5.4
    Medium

    CVE-2024-48246

    Last Modified: 31 Dec 2025

    Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.

    Published: 5 Mar 2025
    8.8
    High

    CVE-2024-51144

    Last Modified: 15 Apr 2026

    Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

    Published: 5 Mar 2025
    7.5
    High

    CVE-2024-53458

    Last Modified: 23 Sept 2025

    Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.

    Published: 5 Mar 2025
    8.1
    High

    CVE-2024-57174

    Last Modified: 15 Apr 2026

    A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-25362

    Last Modified: 15 Apr 2026

    A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-25632

    Last Modified: 9 Apr 2025

    Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27638

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-27639

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27641

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27640

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows SQL Injection V-2024-012.

    Published: 5 Mar 2025
    7.8
    High

    CVE-2025-27644

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27646

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27647

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Authentication V-2024-002.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27649

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27650

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-2023-013.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27652

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: rfIDEAS V-2023-015.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2025-27653

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Preauthenticated Cross Site Scripting (XSS): Badge Registration V-2023-012.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27655

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: CPA v1 V-2023-009.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27657

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27658

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Authentication Bypass OVE-20230524-0001.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27659

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows SQL Injection OVE-20230524-0002.

    Published: 5 Mar 2025
    5.4
    Medium

    CVE-2025-27660

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross Site Scripting OVE-20230524-0003.

    Published: 5 Mar 2025
    9.1
    Critical

    CVE-2025-27661

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27663

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-27664

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-0008.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27665

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Antivirus Protection and thus drivers can have known malicious code OVE-20230524-0009.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27666

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Authorization Checks OVE-20230524-0010.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27667

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumeration OVE-20230524-0011.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27668

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via Iframe OVE-20230524-0012.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27674

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Hardcoded IdP Key V-2023-006.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27670

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-20230524-0014.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27671

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27672

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.

    Published: 5 Mar 2025
    9.1
    Critical

    CVE-2025-27673

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cookie Returned in Response Body OVE-20230524-0017.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2025-27676

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Reports V-2023-002.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27677

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interaction V-2022-002.

    Published: 5 Mar 2025
    9.3
    Critical

    CVE-2025-23410

    Last Modified: 15 Apr 2026

    When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-21092

    Last Modified: 15 Apr 2026

    GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves or others.

    Published: 4 Mar 2025
    9.3
    Critical

    CVE-2025-1316

    Last Modified: 30 Oct 2025

    Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1962

    Last Modified: 2 Apr 2025

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1961

    Last Modified: 29 Apr 2025

    A vulnerability has been found in SourceCodester Best Church Management Software 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/web_crud.php. The manipulation of the argument encryption leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1959

    Last Modified: 3 Apr 2025

    A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The manipulation of the argument login_id/login_key leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1958

    Last Modified: 15 Oct 2025

    A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.1
    Medium

    CVE-2025-1957

    Last Modified: 3 Apr 2025

    A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /BBfile/Blood/o+.php. The manipulation of the argument Bloodname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    9.3
    Critical

    CVE-2025-27510

    Last Modified: 15 Apr 2026

    conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the PyPi repository nor registered by any entity. If conda-oci-mirror is taken over by a threat actor, it can result in remote code execution.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1956

    Last Modified: 3 Apr 2025

    A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025