CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2025-1955

    Last Modified: 21 May 2025

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipulation of the argument username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1954

    Last Modified: 8 May 2025

    A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2024-8000

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication during ASU would be impacted with this bug.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2024-9135

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.

    Published: 4 Mar 2025
    7.2
    High

    CVE-2025-1080

    Last Modified: 10 Dec 2025

    LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

    Published: 4 Mar 2025
    2.1
    Low

    CVE-2025-1953

    Last Modified: 15 Apr 2026

    A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.3.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 4 Mar 2025
    9.1
    Critical

    CVE-2025-1260

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.

    Published: 4 Mar 2025
    7.7
    High

    CVE-2025-1259

    Last Modified: 15 Apr 2026

    On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1952

    Last Modified: 3 Apr 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. The manipulation of the argument username/mobileno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1949

    Last Modified: 23 Apr 2025

    A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1969

    Last Modified: 15 Apr 2026

    Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1947

    Last Modified: 29 Jan 2026

    A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1946

    Last Modified: 29 Jan 2026

    A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF. The manipulation of the argument id leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2020-3122

    Last Modified: 31 Jul 2025

    A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2019-1815

    Last Modified: 15 Apr 2026

    A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the files holding debugging and maintenance information, and is only exploitable when the local status page is enabled on the device. An attacker exploiting this vulnerability may obtain access to wireless pre-shared keys, Site-to-Site VPN key and other sensitive information. Under certain circumstances, this information may allow an attacker to obtain administrative-level access to the device.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2024-10930

    Last Modified: 5 Feb 2026

    An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

    Published: 4 Mar 2025
    7.7
    High

    CVE-2024-41147

    Last Modified: 26 Aug 2025

    An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 4 Mar 2025
    4.6
    Medium

    CVE-2025-27402

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740414959 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.

    Published: 4 Mar 2025
    4.6
    Medium

    CVE-2025-27401

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle through all the filters of all reports of the instance and delete them. The malicious user only needs to have access to one tracker. This would result in the loss of all criteria filters forcing users and tracker admins to re-create them. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740498975 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.

    Published: 4 Mar 2025
    4.1
    Medium

    CVE-2025-27156

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This vulnerability is fixed in Tuleap Community Edition 16.4.99.1740567344 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-27150

    Last Modified: 22 Aug 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used by support teams that should not have access to this password. The vulnerability is fixed in Tuleap Community Edition 16.4.99.1740492866 and Tuleap Enterprise Edition 16.4-6 and 16.3-11.

    Published: 4 Mar 2025
    9
    Critical

    CVE-2025-27507

    Last Modified: 26 Aug 2025

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specific IAM roles, to modify sensitive settings. While several endpoints are affected, the most critical vulnerability lies in the ability to manipulate LDAP configurations. Customers who do not utilize LDAP for authentication are not at risk from the most severe aspects of this vulnerability. However, upgrading to the patched version to address all identified issues is strongly recommended. This vulnerability is fixed in 2.71.0, 2.70.1, ,2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5, and 2.63.8.

    Published: 4 Mar 2025
    6.1
    Medium

    CVE-2025-27155

    Last Modified: 15 Apr 2026

    Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting pineconesim.

    Published: 4 Mar 2025
    9.3
    Critical

    CVE-2024-11957

    Last Modified: 15 Apr 2026

    Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-27111

    Last Modified: 3 Nov 2025

    Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sendfile-Type header. An attacker can exploit this by injecting escape sequences (such as newline characters) into the header, resulting in log injection. This vulnerability is fixed in 2.2.12, 3.0.13, and 3.1.11.

    Published: 4 Mar 2025
    8.6
    High

    CVE-2025-1424

    Last Modified: 15 Apr 2026

    A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This issue affects InkPad Color 3 in version U743k3.6.8.3671.

    Published: 4 Mar 2025
    4.7
    Medium

    CVE-2025-1425

    Last Modified: 15 Apr 2026

    A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.

    Published: 4 Mar 2025
    8.6
    High

    CVE-2024-9149

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection. This issue affects E-Commerce Website Template: before v1.5.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2025-27425

    Last Modified: 20 Apr 2026

    Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first. This vulnerability was fixed in Firefox for iOS 136.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2025-27424

    Last Modified: 20 Apr 2026

    Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vulnerability was fixed in Firefox for iOS 136.

    Published: 4 Mar 2025
    5.4
    Medium

    CVE-2025-27426

    Last Modified: 20 Apr 2026

    Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2025-1938

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    8.2
    High

    CVE-2025-1943

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

    Published: 4 Mar 2025
    7.5
    High

    CVE-2025-1937

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    7.3
    High

    CVE-2025-1936

    Last Modified: 20 Apr 2026

    jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2025-1935

    Last Modified: 21 Apr 2026

    A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2025-1942

    Last Modified: 20 Apr 2026

    When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.

    Published: 4 Mar 2025
    9.1
    Critical

    CVE-2025-1941

    Last Modified: 20 Apr 2026

    Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2025-1934

    Last Modified: 20 Apr 2026

    It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1940

    Last Modified: 20 Apr 2026

    A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.*. This vulnerability was fixed in Firefox 136.

    Published: 4 Mar 2025
    8.1
    High

    CVE-2025-1932

    Last Modified: 20 Apr 2026

    An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    7.5
    High

    CVE-2025-1931

    Last Modified: 20 Apr 2026

    It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    7.6
    High

    CVE-2025-1933

    Last Modified: 20 Apr 2026

    On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    8.8
    High

    CVE-2025-1930

    Last Modified: 20 Apr 2026

    On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

    Published: 4 Mar 2025
    3.9
    Low

    CVE-2025-1939

    Last Modified: 20 Apr 2026

    Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability was fixed in Firefox 136.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1925

    Last Modified: 23 Jun 2025

    A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-22226

    Last Modified: 26 Feb 2026

    VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

    Published: 4 Mar 2025
    8.2
    High

    CVE-2025-22225

    Last Modified: 26 Feb 2026

    VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

    Published: 4 Mar 2025
    9.3
    Critical

    CVE-2025-22224

    Last Modified: 26 Feb 2026

    VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

    Published: 4 Mar 2025
    6.4
    Medium

    CVE-2025-0370

    Last Modified: 22 Apr 2026

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Mar 2025