CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-13888

    Last Modified: 8 Apr 2026

    The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

    Published: 20 Feb 2025
    6.4
    Medium

    CVE-2024-13155

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: Since the widget code isn't part of the code base, to apply the patch, the affected widget: Transparent Split Hero must be deleted and reinstalled manually.

    Published: 20 Feb 2025
    7.2
    High

    CVE-2025-26856

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs in to the affected product with an administrative account and manipulates requests for a certain screen operation, an arbitrary OS command may be executed. This vulnerability was reported on a different screen operation from CVE-2025-20617.

    Published: 20 Feb 2025
    6.4
    Medium

    CVE-2024-13445

    Last Modified: 8 Apr 2026

    The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2024-49780

    Last Modified: 15 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. An attacker with privileges to perform Import Configuration could send a specially crafted http request containing "dot dot" sequences (/../) in the file name parameter used in Import Configuration to write files to arbitrary locations outside of the specified directory and possibly overwrite arbitrary files.

    Published: 20 Feb 2025
    6.8
    Medium

    CVE-2024-49782

    Last Modified: 15 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could exploit this vulnerability to gain access to sensitive information disclosed through email notifications generated by OpenPages or disrupt notification delivery.

    Published: 20 Feb 2025
    4.3
    Medium

    CVE-2024-43196

    Last Modified: 15 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0  application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses.

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2024-49355

    Last Modified: 15 Aug 2025

    IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.

    Published: 20 Feb 2025
    7.8
    High

    CVE-2025-1492

    Last Modified: 27 Mar 2026

    Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

    Published: 20 Feb 2025
    8.2
    High

    CVE-2025-1293

    Last Modified: 18 Dec 2025

    Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

    Published: 20 Feb 2025
    5.9
    Medium

    CVE-2025-1223

    Last Modified: 6 Aug 2025

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

    Published: 20 Feb 2025
    5.9
    Medium

    CVE-2025-1222

    Last Modified: 6 Aug 2025

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2025-27218

    Last Modified: 15 Apr 2026

    Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2025-24947

    Last Modified: 15 Apr 2026

    A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This is caused by XXH32 usage.

    Published: 20 Feb 2025
    7.5
    High

    CVE-2024-57716

    Last Modified: 15 Apr 2026

    An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26310

    Last Modified: 17 Apr 2025

    Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted ABC file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26307

    Last Modified: 17 Apr 2025

    A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26306

    Last Modified: 17 Apr 2025

    A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 20 Feb 2025
    8.2
    High

    CVE-2025-26304

    Last Modified: 22 Apr 2025

    A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.

    Published: 20 Feb 2025
    6
    Medium

    CVE-2025-25968

    Last Modified: 30 Sept 2025

    DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml), attackers can bypass access controls, leading to account takeover and potential privilege escalation.

    Published: 20 Feb 2025
    6.1
    Medium

    CVE-2025-25960

    Last Modified: 22 Apr 2025

    Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.

    Published: 20 Feb 2025
    9.8
    Critical

    CVE-2025-25663

    Last Modified: 17 Mar 2025

    A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.

    Published: 20 Feb 2025
    9.8
    Critical

    CVE-2025-25667

    Last Modified: 17 Mar 2025

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

    Published: 20 Feb 2025
    9.8
    Critical

    CVE-2025-25676

    Last Modified: 10 Apr 2025

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2025-25958

    Last Modified: 22 Apr 2025

    Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.

    Published: 20 Feb 2025
    8.2
    High

    CVE-2025-26305

    Last Modified: 22 Apr 2025

    A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26308

    Last Modified: 17 Apr 2025

    A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26309

    Last Modified: 17 Apr 2025

    A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-26311

    Last Modified: 17 Apr 2025

    Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted SWF file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2023-51323

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2023-51331

    Last Modified: 4 Nov 2025

    PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51338

    Last Modified: 4 Nov 2025

    PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2025-25973

    Last Modified: 23 Sept 2025

    A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51330

    Last Modified: 4 Nov 2025

    PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51306

    Last Modified: 4 Nov 2025

    PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters.

    Published: 20 Feb 2025
    4.3
    Medium

    CVE-2023-51309

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51312

    Last Modified: 4 Nov 2025

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51315

    Last Modified: 4 Nov 2025

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters.

    Published: 20 Feb 2025
    8.8
    High

    CVE-2023-51313

    Last Modified: 23 Apr 2025

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51318

    Last Modified: 4 Nov 2025

    PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2023-51320

    Last Modified: 4 Nov 2025

    PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51325

    Last Modified: 4 Nov 2025

    PHPJabbers Shared Asset Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2023-51327

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    4.3
    Medium

    CVE-2023-51332

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    5.3
    Medium

    CVE-2023-51334

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    5.4
    Medium

    CVE-2023-51337

    Last Modified: 4 Nov 2025

    PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2023-51339

    Last Modified: 4 Nov 2025

    A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

    Published: 20 Feb 2025
    9.8
    Critical

    CVE-2024-54756

    Last Modified: 15 Apr 2026

    A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.

    Published: 20 Feb 2025
    6.5
    Medium

    CVE-2024-55457

    Last Modified: 15 Apr 2026

    MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information.

    Published: 20 Feb 2025
    7.7
    High

    CVE-2024-46933

    Last Modified: 15 Apr 2026

    An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.

    Published: 20 Feb 2025