CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2025-20021

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-20011

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-0587

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    8.8
    High

    CVE-2025-1639

    Last Modified: 20 Apr 2026

    The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2025-1321

    Last Modified: 20 Apr 2026

    The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2025-0912

    Last Modified: 22 Apr 2026

    The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2024-13686

    Last Modified: 8 Apr 2026

    The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the themes settings.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1901

    Last Modified: 6 Mar 2025

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1900

    Last Modified: 6 Mar 2025

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /add-table.php. The manipulation of the argument tableno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1899

    Last Modified: 5 Mar 2025

    A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1898

    Last Modified: 12 Jul 2025

    A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2024-13685

    Last Modified: 14 May 2025

    The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1897

    Last Modified: 13 Jul 2025

    A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1896

    Last Modified: 12 Jul 2025

    A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2025-1895

    Last Modified: 5 Mar 2025

    A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1894

    Last Modified: 5 Mar 2025

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1695

    Last Modified: 3 Nov 2025

    In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS).  There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1893

    Last Modified: 6 Mar 2025

    A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. The patch is named e31e9965f00d9c744a7f728497cb4f3e97744ee8. It is recommended to apply a patch to fix this issue.

    Published: 4 Mar 2025
    4.8
    Medium

    CVE-2025-1892

    Last Modified: 5 Mar 2025

    A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    7.5
    High

    CVE-2021-41719

    Last Modified: 15 Apr 2026

    Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2025-26320

    Last Modified: 7 Jul 2025

    t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2025-26319

    Last Modified: 24 Jun 2025

    FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

    Published: 4 Mar 2025
    10
    Critical

    CVE-2024-50704

    Last Modified: 28 May 2025

    Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2025-26849

    Last Modified: 7 Jul 2025

    There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive information such as firewall rules.

    Published: 4 Mar 2025
    7.8
    High

    CVE-2020-23438

    Last Modified: 26 Mar 2025

    Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

    Published: 4 Mar 2025
    7.1
    High

    CVE-2024-50705

    Last Modified: 21 May 2025

    Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2024-50706

    Last Modified: 28 May 2025

    Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

    Published: 4 Mar 2025
    10
    Critical

    CVE-2024-50707

    Last Modified: 28 May 2025

    Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.

    Published: 4 Mar 2025
    8.6
    High

    CVE-2024-48248

    Last Modified: 5 Nov 2025

    NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

    Published: 4 Mar 2025
    7.2
    High

    CVE-2025-25426

    Last Modified: 12 Jun 2025

    yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.

    Published: 4 Mar 2025
    4.6
    Medium

    CVE-2025-26091

    Last Modified: 21 May 2025

    A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2025-26136

    Last Modified: 24 Jun 2025

    A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2025-26182

    Last Modified: 24 Jun 2025

    An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2025-26202

    Last Modified: 15 Apr 2026

    Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page

    Published: 4 Mar 2025
    5.8
    Medium

    CVE-2025-26318

    Last Modified: 15 Apr 2026

    hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2025-1891

    Last Modified: 28 Aug 2025

    A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1890

    Last Modified: 5 Mar 2025

    A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    2.3
    Low

    CVE-2025-1882

    Last Modified: 12 Jul 2025

    A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1881

    Last Modified: 12 Jul 2025

    A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Video Footage/Live Video Stream. The manipulation leads to improper access controls. The attack can be launched remotely. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

    Published: 3 Mar 2025
    1
    Low

    CVE-2025-1880

    Last Modified: 12 Jul 2025

    A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

    Published: 3 Mar 2025
    4.9
    Medium

    CVE-2024-51966

    Last Modified: 10 Apr 2025

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

    Published: 3 Mar 2025
    4.8
    Medium

    CVE-2024-51963

    Last Modified: 10 Apr 2025

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

    Published: 3 Mar 2025
    8.7
    High

    CVE-2024-51962

    Last Modified: 13 Feb 2026

    A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.

    Published: 3 Mar 2025
    7.5
    High

    CVE-2024-51961

    Last Modified: 10 Apr 2025

    There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.

    Published: 3 Mar 2025
    4.8
    Medium

    CVE-2024-51960

    Last Modified: 10 Apr 2025

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

    Published: 3 Mar 2025
    4.8
    Medium

    CVE-2024-51959

    Last Modified: 10 Apr 2025

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

    Published: 3 Mar 2025
    4.9
    Medium

    CVE-2024-51958

    Last Modified: 10 Apr 2025

    There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory.  There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.

    Published: 3 Mar 2025
    4.8
    Medium

    CVE-2024-51957

    Last Modified: 10 Apr 2025

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

    Published: 3 Mar 2025
    4.8
    Medium

    CVE-2024-51956

    Last Modified: 10 Apr 2025

    There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required to execute this attack are high, requiring publisher capabilities. The impact is low to both confidentiality and integrity while having no impact to availability.

    Published: 3 Mar 2025
    8.5
    High

    CVE-2024-51954

    Last Modified: 13 Feb 2026

    There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS Server instance. Successful exploitation results in unauthorized access to protected services outside the attacker’s originally assigned authorization boundary, constituting a scope change. If exploited, this issue would have a high impact on confidentiality, a low impact on integrity, and no impact on the availability of the software.

    Published: 3 Mar 2025