CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-20644

    Last Modified: 17 Feb 2026

    In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01525673; Issue ID: MSV-2747.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1845

    Last Modified: 28 May 2025

    A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the function examExportPDF of the file /admin/plan/examExportPDF. The manipulation of the argument s leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1844

    Last Modified: 28 May 2025

    A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. Affected is an unknown function of the file /CDGServer3/logManagement/backupLogDetail.jsp. The manipulation of the argument logTaskId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1843

    Last Modified: 2 Sept 2025

    A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20250211. This issue affects the function select of the file com/xq/tmall/dao/ProductMapper.java. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    5.3
    Medium

    CVE-2025-1842

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1841

    Last Modified: 28 May 2025

    A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the argument startDate/endDate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2025
    8.1
    High

    CVE-2025-23368

    Last Modified: 30 Jun 2026

    A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-27371

    Last Modified: 15 Apr 2026

    In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism is used, there are ambiguities in the audience values of JWTs sent to authorization servers. The affected RFCs may include RFC 7523, and also RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR).

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-27370

    Last Modified: 15 Apr 2026

    OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt authentication mechanism is used, a malicious Authorization Server could trick a Client into writing attacker-controlled values into the audience, including token endpoints or issuer identifiers of other Authorization Servers. The malicious Authorization Server could then use these private key JWTs to impersonate the Client.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-25952

    Last Modified: 12 Dec 2025

    An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-55064

    Last Modified: 12 Jul 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter.

    Published: 3 Mar 2025
    4.9
    Medium

    CVE-2024-53386

    Last Modified: 27 Jun 2025

    Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2025-27584

    Last Modified: 27 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name parameter at /rest/staffResource/update.

    Published: 3 Mar 2025
    5.1
    Medium

    CVE-2023-49031

    Last Modified: 11 Jul 2025

    Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2025-25949

    Last Modified: 29 Jan 2026

    A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.

    Published: 3 Mar 2025
    5.8
    Medium

    CVE-2025-27219

    Last Modified: 3 Nov 2025

    In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-51091

    Last Modified: 7 Jul 2025

    Cross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package

    Published: 3 Mar 2025
    4.9
    Medium

    CVE-2024-53382

    Last Modified: 27 Jun 2025

    Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

    Published: 3 Mar 2025
    5.1
    Medium

    CVE-2024-53384

    Last Modified: 7 Jul 2025

    A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

    Published: 3 Mar 2025
    8.8
    High

    CVE-2024-53387

    Last Modified: 7 Jul 2025

    A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.

    Published: 3 Mar 2025
    8.8
    High

    CVE-2024-53388

    Last Modified: 7 Jul 2025

    A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-55570

    Last Modified: 15 Apr 2026

    /api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenticated users of the application to increase their privileges by sending a single HTTP PUT request with rolename=Administrator, aka incorrect access control.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2024-57240

    Last Modified: 10 Jul 2025

    A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.

    Published: 3 Mar 2025
    6.1
    Medium

    CVE-2025-25939

    Last Modified: 30 Dec 2025

    Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

    Published: 3 Mar 2025
    9.1
    Critical

    CVE-2025-25948

    Last Modified: 29 Jan 2026

    Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

    Published: 3 Mar 2025
    8.1
    High

    CVE-2025-25950

    Last Modified: 12 Dec 2025

    Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

    Published: 3 Mar 2025
    7.5
    High

    CVE-2025-25951

    Last Modified: 12 Dec 2025

    An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-25953

    Last Modified: 12 Dec 2025

    Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive information.

    Published: 3 Mar 2025
    8.8
    High

    CVE-2025-25967

    Last Modified: 6 Mar 2025

    Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.

    Published: 3 Mar 2025
    9
    Critical

    CVE-2025-26206

    Last Modified: 7 Jul 2025

    Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component

    Published: 3 Mar 2025
    4
    Medium

    CVE-2025-27220

    Last Modified: 3 Nov 2025

    In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

    Published: 3 Mar 2025
    3.2
    Low

    CVE-2025-27221

    Last Modified: 3 Nov 2025

    In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

    Published: 3 Mar 2025
    9.1
    Critical

    CVE-2025-27583

    Last Modified: 27 Jun 2025

    Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

    Published: 3 Mar 2025
    5.4
    Medium

    CVE-2025-27585

    Last Modified: 27 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Print Name parameter at /rest/staffResource/update.

    Published: 3 Mar 2025
    9
    Critical

    CVE-2025-27590

    Last Modified: 12 Jul 2025

    In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1840

    Last Modified: 5 Jun 2025

    A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been rated as critical. Affected by this issue is some unknown functionality of the file /CDGServer3/workflowE/useractivate/updateorg.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1836

    Last Modified: 15 Apr 2026

    A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of the component Edit Insight Handler. The manipulation of the argument Service Name leads to csv injection. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1835

    Last Modified: 15 Apr 2026

    A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /app/controller/Api.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1834

    Last Modified: 26 May 2025

    A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1833

    Last Modified: 26 May 2025

    A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. Affected by this issue is the function sendNotice of the file src/main/java/com/futvan/z/erp/customer_notice/Customer_noticeAction.java of the component HTTP Request Handler. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1832

    Last Modified: 26 May 2025

    A vulnerability classified as critical was found in zj1983 zz up to 2024-8. Affected by this vulnerability is the function getUserList of the file src/main/java/com/futvan/z/system/zrole/ZroleAction.java. The manipulation of the argument roleid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1831

    Last Modified: 26 May 2025

    A vulnerability classified as critical has been found in zj1983 zz up to 2024-8. Affected is the function GetDBUser of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    4.8
    Medium

    CVE-2025-1830

    Last Modified: 26 May 2025

    A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component Customer Information Handler. The manipulation of the argument Customer Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1829

    Last Modified: 3 Apr 2025

    A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mtkhnatEnable leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1821

    Last Modified: 26 May 2025

    A vulnerability was found in zj1983 zz up to 2024-8 and classified as critical. Affected by this issue is the function getUserOrgForUserId of the file src/main/java/com/futvan/z/system/zorg/ZorgAction.java. The manipulation of the argument userID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1820

    Last Modified: 26 May 2025

    A vulnerability has been found in zj1983 zz up to 2024-8 and classified as critical. Affected by this vulnerability is the function getOaWid of the file src/main/java/com/futvan/z/system/zworkflow/ZworkflowAction.java. The manipulation of the argument tableId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1819

    Last Modified: 16 Jul 2025

    A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform/telnet. The manipulation of the argument lan_ip leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Mar 2025
    5.3
    Medium

    CVE-2025-1818

    Last Modified: 26 May 2025

    A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.upload. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 2 Mar 2025
    2
    Low

    CVE-2024-55907

    Last Modified: 1 Sept 2025

    IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation.

    Published: 2 Mar 2025
    2.4
    Low

    CVE-2025-0895

    Last Modified: 1 Sept 2025

    IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.

    Published: 2 Mar 2025