CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2025-27297

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in guelben Bravo Search & Replace bravo-search-and-replace allows Blind SQL Injection.This issue affects Bravo Search & Replace: from n/a through <= 1.0.

    Published: 24 Feb 2025
    7.2
    High

    CVE-2025-27296

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue revenueflex-easy-ads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through <= 1.5.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-27294

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in platcom WP-Asambleas wp-asambleas allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Asambleas: from n/a through <= 2.85.0.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-27290

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in seyyed-amir Erima Zarinpal Donate erima-zarinpal-donate allows Cross Site Request Forgery.This issue affects Erima Zarinpal Donate: from n/a through <= 1.0.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27280

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alobaidi Archive Page archive-page allows DOM-Based XSS.This issue affects Archive Page: from n/a through <= 1.0.2.

    Published: 24 Feb 2025
    7.1
    High

    CVE-2025-27277

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v01 allows Cross Site Request Forgery.This issue affects Add Linked Images To Gallery: from n/a through <= 1.4.

    Published: 24 Feb 2025
    8.8
    High

    CVE-2025-27276

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows Privilege Escalation.This issue affects Photo Gallery ( Responsive ): from n/a through <= 4.0.

    Published: 24 Feb 2025
    7.5
    High

    CVE-2025-27272

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vinagecko VG PostCarousel vg-postcarousel allows PHP Local File Inclusion.This issue affects VG PostCarousel: from n/a through <= 1.1.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27266

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ignacio Perez Hover Image Button hover-image-button allows DOM-Based XSS.This issue affects Hover Image Button: from n/a through <= 1.1.2.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2025-27265

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress google-maps-for-wordpress allows DOM-Based XSS.This issue affects Google Maps for WordPress: from n/a through <= 1.0.3.

    Published: 24 Feb 2025
    8.8
    High

    CVE-2024-12918

    Last Modified: 1 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection. This issue affects Health4All: before 10.01.2025.

    Published: 24 Feb 2025
    8.3
    High

    CVE-2024-12917

    Last Modified: 1 Jun 2026

    Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025.

    Published: 24 Feb 2025
    8.8
    High

    CVE-2024-12916

    Last Modified: 1 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection. This issue affects Life4All: before 10.01.2025.

    Published: 24 Feb 2025
    4.7
    Medium

    CVE-2025-0545

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tekrom Technology T-Soft E-Commerce allows Cross-Site Scripting (XSS). This issue affects T-Soft E-Commerce: before v5.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2024-5174

    Last Modified: 15 Apr 2026

    A flaw in Gliffy results in broken authentication through the reset functionality of the application.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-1632

    Last Modified: 25 Mar 2025

    A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    4.7
    Medium

    CVE-2025-1488

    Last Modified: 22 Apr 2026

    The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if 1. they can successfully trick them into performing an action and 2. the plugin is activated but not configured.

    Published: 24 Feb 2025
    9.9
    Critical

    CVE-2025-20051

    Last Modified: 18 Aug 2025

    Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.

    Published: 24 Feb 2025
    9.6
    Critical

    CVE-2025-24490

    Last Modified: 1 Oct 2025

    Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.

    Published: 24 Feb 2025
    9.9
    Critical

    CVE-2025-25279

    Last Modified: 2 Oct 2025

    Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.

    Published: 24 Feb 2025
    3.1
    Low

    CVE-2025-1412

    Last Modified: 1 Oct 2025

    Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

    Published: 24 Feb 2025
    4.3
    Medium

    CVE-2025-24526

    Last Modified: 1 Oct 2025

    Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it

    Published: 24 Feb 2025
    —
    Unknown

    CVE-2025-1631

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Feb 2025
    5.1
    Medium

    CVE-2025-1629

    Last Modified: 15 Apr 2026

    A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1618

    Last Modified: 29 Jan 2026

    A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-1617

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The manipulation of the argument SSID leads to cross site scripting. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.1
    Medium

    CVE-2025-1616

    Last Modified: 24 Feb 2025

    A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-1615

    Last Modified: 28 Feb 2025

    A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-1614

    Last Modified: 28 Feb 2025

    A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argument pf_Description leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-1613

    Last Modified: 28 Feb 2025

    A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of the argument url_IP leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.1
    Medium

    CVE-2025-1612

    Last Modified: 21 May 2025

    A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation of the argument SSID leads to cross site scripting. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    8.5
    High

    CVE-2024-55898

    Last Modified: 3 Jul 2025

    IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

    Published: 24 Feb 2025
    5.1
    Medium

    CVE-2025-1611

    Last Modified: 2 Jul 2025

    A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    6.1
    Medium

    CVE-2024-13822

    Last Modified: 7 May 2025

    The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2024-13605

    Last Modified: 7 May 2025

    The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Feb 2025
    5.4
    Medium

    CVE-2024-12308

    Last Modified: 7 May 2025

    The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1610

    Last Modified: 4 Nov 2025

    A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of the file /goform/set_blacklist. The manipulation of the argument mac/enable leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1609

    Last Modified: 4 Nov 2025

    A vulnerability has been found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this vulnerability is the function websGetVar of the file /goform/set_cmd. The manipulation of the argument cmd leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1608

    Last Modified: 4 Nov 2025

    A vulnerability, which was classified as critical, was found in LB-LINK AC1900 Router 1.0.2. Affected is the function websGetVar of the file /goform/set_manpwd. The manipulation of the argument routepwd  leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1607

    Last Modified: 14 May 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Best Employee Management System 1.0. This issue affects some unknown processing of the file /admin/salary_slip.php. The manipulation of the argument id leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1606

    Last Modified: 28 Feb 2025

    A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of the file /admin/backup/backups.php. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1599

    Last Modified: 24 Feb 2025

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argument old_cat_img leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Feb 2025
    9.1
    Critical

    CVE-2025-26201

    Last Modified: 15 Apr 2026

    Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

    Published: 24 Feb 2025
    5.7
    Medium

    CVE-2025-25209

    Last Modified: 15 Apr 2026

    The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those secrets over HTTP connection, as long the attacker knows the name of the targeted secrets and those secrets are limited to one line only.

    Published: 24 Feb 2025
    5.7
    Medium

    CVE-2025-25208

    Last Modified: 15 Apr 2026

    A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

    Published: 24 Feb 2025
    5.7
    Medium

    CVE-2025-25207

    Last Modified: 15 Apr 2026

    The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access can add a large number of those callbacks to be executed by Authorino and as the authentication policy is enforced by a single instance of the service, this leada to a Denial of Service in Authorino while processing the post-authorization callbacks.

    Published: 24 Feb 2025
    5.4
    Medium

    CVE-2024-53543

    Last Modified: 15 Apr 2026

    NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.

    Published: 24 Feb 2025
    7.5
    High

    CVE-2025-1634

    Last Modified: 6 May 2026

    A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

    Published: 24 Feb 2025
    10
    Critical

    CVE-2025-27364

    Last Modified: 15 Apr 2026

    In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-26803

    Last Modified: 13 Jul 2025

    The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

    Published: 24 Feb 2025