CVE Feed

    Dashboard / CVE

    2.3
    Low

    CVE-2024-51539

    Last Modified: 21 Jan 2026

    The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This vulnerability can only be exploited locally on the affected system. A high-privilege attacker with access to the system could potentially exploit this vulnerability, leading to the disclosure of non-sensitive information that does not include any customer data.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1262

    Last Modified: 21 Apr 2026

    The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2024-11955

    Last Modified: 4 Mar 2025

    A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument redirect leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.0.18 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1676

    Last Modified: 29 Jan 2026

    A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file /pdf2swf. The manipulation of the argument file leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 25 Feb 2025
    6.4
    Medium

    CVE-2024-13695

    Last Modified: 8 Apr 2026

    The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2024-13693

    Last Modified: 8 Apr 2026

    The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.

    Published: 25 Feb 2025
    4.3
    Medium

    CVE-2024-13494

    Last Modified: 8 Apr 2026

    The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.25.2. This is due to missing or incorrect nonce validation on the 'wfu_file_details' function. This makes it possible for unauthenticated attackers to modify user data details associated with uploaded files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 25 Feb 2025
    8.2
    High

    CVE-2025-1675

    Last Modified: 12 Jul 2025

    The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is large enough to contain the copied data.

    Published: 25 Feb 2025
    8.2
    High

    CVE-2025-1674

    Last Modified: 28 Feb 2025

    A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.

    Published: 25 Feb 2025
    8.2
    High

    CVE-2025-1673

    Last Modified: 28 Feb 2025

    A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1063

    Last Modified: 21 Apr 2026

    The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including API keys and tokens.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-1128

    Last Modified: 21 Apr 2026

    The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible.

    Published: 25 Feb 2025
    7.5
    High

    CVE-2025-1648

    Last Modified: 21 Apr 2026

    The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 25 Feb 2025
    7.2
    High

    CVE-2025-22210

    Last Modified: 4 Jun 2025

    A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

    Published: 25 Feb 2025
    6.9
    Medium

    CVE-2025-1646

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx of the component ASPX File Handler. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1645

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in Benner Connecta 1.0.5330. Affected by this vulnerability is an unknown functionality of the file /Usuarios/Usuario/EditarLogado/. The manipulation of the argument Handle leads to improper control of resource identifiers. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 Feb 2025
    3.5
    Low

    CVE-2024-10545

    Last Modified: 15 May 2025

    The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 25 Feb 2025
    3.6
    Low

    CVE-2025-27145

    Last Modified: 19 Sept 2025

    copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging the file into copyparty's Web-UI, an attacker could execute arbitrary javascript with the same privileges as that user. For example, this could give unintended read-access to files owned by that user. The bug is triggered by the drag-drop action itself; it is not necessary to actually initiate the upload. The file must be empty (zero bytes). Note that, as a general-purpose webserver, it is intentionally possible to upload HTML-files with arbitrary javascript in `<script>` tags, which will execute when the file is opened. The difference is that this vulnerability would trigger execution of javascript during the act of uploading, and not when the uploaded file was opened. Version 1.16.15 contains a fix.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1644

    Last Modified: 25 Feb 2025

    A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais/SG_Gravar. The manipulation of the argument idItAg leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 1.2.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1643

    Last Modified: 25 Feb 2025

    A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file /DadosPessoais/SG_AlterarSenha. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    5.3
    Medium

    CVE-2025-1642

    Last Modified: 25 Feb 2025

    A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /AGE0000700/GetImageMedico?fooId=1. The manipulation of the argument fooId leads to improper control of resource identifiers. The attack can be initiated remotely. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    6.9
    Medium

    CVE-2025-1641

    Last Modified: 25 Feb 2025

    A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been classified as critical. This affects an unknown part of the file /AGE0000700/GetHorariosDoDia?idespec=0&idproced=1103&data=2025-02-25+19%3A25&agserv=0&convenio=1&localatend=1&idplano=5&pesfis=01&idprofissional=0&target=.horarios--dia--d0&_=1739371223797. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    6.9
    Medium

    CVE-2025-1640

    Last Modified: 25 Feb 2025

    A vulnerability was found in Benner ModernaNet up to 1.1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /Home/JS_CarregaCombo?formName=DADOS_PESSOAIS_PLANO&additionalCondition=&insideParameters=&elementToReturn=DADOS_PESSOAIS_PLANO&ordenarPelaDescricao=true&direcaoOrdenacao=asc&_=1739290047295. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version 1.1.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26601

    Last Modified: 29 Jun 2026

    A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing a use-after-free when the alarm eventually triggers.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26599

    Last Modified: 29 Jun 2026

    An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an uninitialized pointer later.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26598

    Last Modified: 29 Jun 2026

    An out-of-bounds write flaw was found in X.Org and Xwayland. The function GetBarrierDevice() searches for the pointer device based on its device ID and returns the matching value, or supposedly NULL, if no match was found. However, the code will return the last element of the list if no matching device ID is found, which can lead to out-of-bounds memory access.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26594

    Last Modified: 29 Jun 2026

    A use-after-free flaw was found in X.Org and Xwayland. The root cursor is referenced in the X server as a global variable. If a client frees the root cursor, the internal reference points to freed memory and causes a use-after-free.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26597

    Last Modified: 29 Jun 2026

    A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zero value of groups, this will cause a buffer overflow because the key actions are of the wrong size.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26595

    Last Modified: 29 Jun 2026

    A buffer overflow flaw was found in X.Org and Xwayland. The code in XkbVModMaskText() allocates a fixed-sized buffer on the stack and copies the names of the virtual modifiers to that buffer. The code fails to check the bounds of the buffer and would copy the data regardless of the size.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26600

    Last Modified: 29 Jun 2026

    A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.

    Published: 25 Feb 2025
    5.7
    Medium

    CVE-2024-34035

    Last Modified: 15 Apr 2026

    An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a significant quantity of E2 Subscription Requests originating from an xApp.

    Published: 25 Feb 2025
    5.7
    Medium

    CVE-2024-34034

    Last Modified: 15 Apr 2026

    An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-25521

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-25520

    Last Modified: 28 Mar 2025

    Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-25519

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-25517

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

    Published: 25 Feb 2025
    9.8
    Critical

    CVE-2025-25516

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

    Published: 25 Feb 2025
    7.8
    High

    CVE-2025-26596

    Last Modified: 29 Jun 2026

    A heap overflow flaw was found in X.Org and Xwayland. The computation of the length in XkbSizeKeySyms() differs from what is written in XkbWriteKeySyms(), which may lead to a heap-based buffer overflow.

    Published: 25 Feb 2025
    8.8
    High

    CVE-2025-25515

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.

    Published: 25 Feb 2025
    4.3
    Medium

    CVE-2024-34036

    Last Modified: 15 Apr 2026

    An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection between a gNB and the Near RT-RIC by inundating the system with a high volume of subscription requests via an xApp.

    Published: 25 Feb 2025
    6.5
    Medium

    CVE-2024-36353

    Last Modified: 15 Apr 2026

    Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentially leading to loss of confidentiality.

    Published: 25 Feb 2025
    6.5
    Medium

    CVE-2025-25514

    Last Modified: 28 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.

    Published: 25 Feb 2025
    6.6
    Medium

    CVE-2025-27144

    Last Modified: 15 Apr 2026

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.

    Published: 24 Feb 2025
    6.9
    Medium

    CVE-2025-27143

    Last Modified: 28 Feb 2025

    Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL parameter in the email verification endpoint and any other endpoint that accepts callback url. While the server blocks fully qualified URLs, it incorrectly allows scheme-less URLs. This results in the browser interpreting the URL as a fully qualified URL, leading to unintended redirection. An attacker can exploit this flaw by crafting a malicious verification link and tricking users into clicking it. Upon successful email verification, the user will be automatically redirected to the attacker's website, which can be used for phishing, malware distribution, or stealing sensitive authentication tokens. This CVE is a bypass of the fix for GHSA-8jhw-6pjj-8723/CVE-2024-56734. Version 1.1.21 contains an updated patch.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-27141

    Last Modified: 28 Feb 2025

    Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with impersonation permissions may be able to see results of cached questions, even if their permissions don’t allow them to see the data. If some user runs a question which gets cached, and then an impersonated user runs that question, then the impersonated user sees the same results as the previous user. These cached results may include data the impersonated user should not have access to. This vulnerability only impacts the Enterprise Edition of Metabase and not the Open Source Edition. Versions 1.53.2, 1.52.11, 1.51.14, and 1.50.36 contains a patch. Versions on the 1.49.X, 1.48.X, and 1.47.X branches are vulnerable but do not have a patch available, so users should upgrade to a major version with an available fix. Disabling question caching is a workaround for this issue.

    Published: 24 Feb 2025
    10
    Critical

    CVE-2025-27140

    Last Modified: 25 Feb 2025

    WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.

    Published: 24 Feb 2025
    4.4
    Medium

    CVE-2025-27137

    Last Modified: 15 Apr 2026

    Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templates. Templates are evaluated using the Pebble template engine. Pebble supports an `include` tag, which allows template authors to include the content of arbitrary files upon evaluation. Prior to version 4.12.6, users of Dependency-Track with the `SYSTEM_CONFIGURATION` permission can abuse the `include` tag by crafting notification templates that `include` sensitive local files, such as `/etc/passwd` or `/proc/1/environ`. By configuring such a template for a notification rule (aka "Alert"), and having it send notifications to a destination controlled by the actor, sensitive information may be leaked. The issue has been fixed in Dependency-Track 4.12.6. In fixed versions, the `include` tag can no longer be used. Usage of the tag will cause template evaluation to fail. As a workaround, avoid assigning the `SYSTEM_CONFIGURATION` permission to untrusted users. The `SYSTEM_CONFIGURATION` permission per default is only granted to members of the `Administrators` team. Assigning this permission to non-administrative users or teams is a security risk in itself, and highly discouraged.

    Published: 24 Feb 2025
    8.1
    High

    CVE-2025-26533

    Last Modified: 6 Aug 2025

    An SQL injection risk was identified in the module list filter within course search.

    Published: 24 Feb 2025
    3.1
    Low

    CVE-2025-26532

    Last Modified: 6 Aug 2025

    Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

    Published: 24 Feb 2025
    3.1
    Low

    CVE-2025-26531

    Last Modified: 7 Aug 2025

    Insufficient capability checks made it possible to disable badges a user does not have permission to access.

    Published: 24 Feb 2025