CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-25079

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simple Select All Text Box simple-select-all-text-box allows Stored XSS.This issue affects Simple Select All Text Box: from n/a through <= 3.2.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25098

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Links in Captions links-in-captions allows Stored XSS.This issue affects Links in Captions: from n/a through <= 1.2.

    Published: 7 Feb 2025
    5.9
    Medium

    CVE-2025-25073

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles easy-wp-tiles allows Stored XSS.This issue affects Easy WP Tiles: from n/a through <= 1.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25082

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Chirkov FlexIDX Home Search flexidx-home-search allows Stored XSS.This issue affects FlexIDX Home Search: from n/a through <= 2.1.2.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2025-25072

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in thunderbax WP Admin Custom Page wp-admin-custom-page allows Stored XSS.This issue affects WP Admin Custom Page: from n/a through <= 1.5.0.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25091

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen Cooliris Gallery nextgen-cooliris-gallery allows Stored XSS.This issue affects NextGen Cooliris Gallery: from n/a through <= 0.7.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-25076

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation graceful-email-obfuscation allows Stored XSS.This issue affects Graceful Email Obfuscation: from n/a through <= 0.2.2.

    Published: 7 Feb 2025
    8.8
    High

    CVE-2025-0304

    Last Modified: 12 Feb 2025

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.

    Published: 7 Feb 2025
    8.8
    High

    CVE-2025-0303

    Last Modified: 12 Feb 2025

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.

    Published: 7 Feb 2025
    5.5
    Medium

    CVE-2025-0302

    Last Modified: 12 Feb 2025

    in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.

    Published: 7 Feb 2025
    9.5
    Critical

    CVE-2025-1077

    Last Modified: 15 Apr 2026

    A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product Delivery Service (PDS) component in specific server configurations where the PDS pipeline utilizes the IPDS pipeline with Message Editor Output Filters enabled. A remote unauthenticated attacker can exploit this vulnerability to send unauthenticated requests to execute the IPDS pipeline with specially crafted Form Properties, enabling remote execution of arbitrary Python code. This vulnerability could lead to a full system compromise of the affected server, particularly if Visual Weather services are run under a privileged user account—contrary to the documented installation best practices. Upgrade to the patched versions 7.3.10 (or higher), 8.6.0 (or higher).

    Published: 7 Feb 2025
    7.8
    High

    CVE-2025-22880

    Last Modified: 11 Jul 2025

    Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

    Published: 7 Feb 2025
    4.3
    Medium

    CVE-2024-13841

    Last Modified: 15 Apr 2026

    The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via the 'bse-elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private and draft posts created with Elementor that they should not have access to.

    Published: 7 Feb 2025
    7.1
    High

    CVE-2024-13352

    Last Modified: 9 Jan 2026

    The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2025-1072

    Last Modified: 6 Aug 2025

    A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.

    Published: 7 Feb 2025
    2.6
    Low

    CVE-2025-22402

    Last Modified: 7 Feb 2025

    Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

    Published: 7 Feb 2025
    6.1
    Medium

    CVE-2024-13492

    Last Modified: 23 May 2025

    The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 7 Feb 2025
    9.8
    Critical

    CVE-2025-1061

    Last Modified: 22 Apr 2026

    The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

    Published: 7 Feb 2025
    6.9
    Medium

    CVE-2025-1086

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Feb 2025
    5.3
    Medium

    CVE-2025-1085

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in Animati PACS up to 1.24.12.09.03. This affects an unknown part of the file /login. The manipulation of the argument p leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2024-55272

    Last Modified: 15 Apr 2026

    An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

    Published: 7 Feb 2025
    4.6
    Medium

    CVE-2024-35106

    Last Modified: 15 Apr 2026

    NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.

    Published: 7 Feb 2025
    —
    Unknown

    CVE-2025-26216

    Last Modified: 14 Mar 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 7 Feb 2025
    —
    Unknown

    CVE-2025-25726

    Last Modified: 2 Mar 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a reservation duplicate of CVE-2024-53427. Notes: All CVE users should reference CVE-2024-53427 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Feb 2025
    —
    Unknown

    CVE-2025-25725

    Last Modified: 2 Mar 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-25724. Reason: This candidate is a reservation duplicate of CVE-2025-25724. Notes: All CVE users should reference CVE-2025-25724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Feb 2025
    5.4
    Medium

    CVE-2024-57278

    Last Modified: 15 Apr 2026

    A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing an attacker to inject malicious JavaScript payloads. When a victim accesses a crafted URL containing the malicious input, the script executes in the victim's browser context.

    Published: 7 Feb 2025
    5.4
    Medium

    CVE-2024-57279

    Last Modified: 15 Apr 2026

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the /setup/index.php endpoint via the returnto parameter. This vulnerability arises due to improper sanitization of user-supplied input, allowing an attacker to inject malicious JavaScript.

    Published: 7 Feb 2025
    7.8
    High

    CVE-2024-48091

    Last Modified: 15 Apr 2026

    Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2024-52881

    Last Modified: 1 May 2025

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.

    Published: 7 Feb 2025
    6.1
    Medium

    CVE-2024-52882

    Last Modified: 1 May 2025

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2024-52883

    Last Modified: 1 May 2025

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2024-52884

    Last Modified: 1 May 2025

    An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2024-55213

    Last Modified: 15 Sept 2025

    Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2024-55214

    Last Modified: 15 Sept 2025

    Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.

    Published: 7 Feb 2025
    9.8
    Critical

    CVE-2024-55215

    Last Modified: 3 Jul 2025

    An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.

    Published: 7 Feb 2025
    6.3
    Medium

    CVE-2024-57248

    Last Modified: 15 Sept 2025

    Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via injecting malicious payloads in HTTP requests to manipulate file paths, bypass access controls, and upload malicious files.

    Published: 7 Feb 2025
    6.5
    Medium

    CVE-2024-57249

    Last Modified: 15 Sept 2025

    Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers, such as the Cookie header, in the request. This bypasses the authentication process and grants attackers access to sensitive image files without proper login credentials.

    Published: 7 Feb 2025
    8
    High

    CVE-2024-57357

    Last Modified: 3 Jul 2025

    An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function sub_4256CC, which allows command injection by injecting 'devpwd'.

    Published: 7 Feb 2025
    7.5
    High

    CVE-2024-57606

    Last Modified: 29 Sept 2025

    SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.

    Published: 7 Feb 2025
    9.8
    Critical

    CVE-2024-57707

    Last Modified: 28 Mar 2025

    An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

    Published: 7 Feb 2025
    8.7
    High

    CVE-2025-0675

    Last Modified: 15 Apr 2026

    Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.

    Published: 6 Feb 2025
    9.3
    Critical

    CVE-2025-0674

    Last Modified: 15 Apr 2026

    Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security.

    Published: 6 Feb 2025
    5.3
    Medium

    CVE-2025-1084

    Last Modified: 10 Oct 2025

    A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2025
    2.3
    Low

    CVE-2025-1083

    Last Modified: 10 Oct 2025

    A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2025
    8.8
    High

    CVE-2025-21342

    Last Modified: 26 Feb 2026

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 6 Feb 2025
    8.8
    High

    CVE-2025-21408

    Last Modified: 13 Feb 2026

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 6 Feb 2025
    6.5
    Medium

    CVE-2025-21283

    Last Modified: 26 Feb 2026

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 6 Feb 2025
    5.3
    Medium

    CVE-2025-21253

    Last Modified: 13 Feb 2026

    Microsoft Edge for IOS and Android Spoofing Vulnerability

    Published: 6 Feb 2025
    8.7
    High

    CVE-2025-21177

    Last Modified: 13 Feb 2026

    Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.

    Published: 6 Feb 2025
    6.5
    Medium

    CVE-2025-21279

    Last Modified: 26 Feb 2026

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 6 Feb 2025