CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-22890

    Last Modified: 4 Feb 2026

    Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained.

    Published: 6 Feb 2025
    7.3
    High

    CVE-2024-13487

    Last Modified: 15 Apr 2026

    The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution via the get_products_price() function in all versions up to, and including, 2.2.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 6 Feb 2025
    4.7
    Medium

    CVE-2025-0522

    Last Modified: 23 May 2025

    The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 6 Feb 2025
    9.3
    Critical

    CVE-2024-51547

    Last Modified: 23 May 2025

    Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 6 Feb 2025
    6.5
    Medium

    CVE-2025-0799

    Last Modified: 12 Aug 2025

    IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.

    Published: 6 Feb 2025
    9.1
    Critical

    CVE-2024-51450

    Last Modified: 8 Aug 2025

    IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

    Published: 6 Feb 2025
    7.8
    High

    CVE-2024-49814

    Last Modified: 8 Aug 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.

    Published: 6 Feb 2025
    5.7
    Medium

    CVE-2025-22936

    Last Modified: 15 Apr 2026

    An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.

    Published: 6 Feb 2025
    7.3
    High

    CVE-2024-57426

    Last Modified: 15 Apr 2026

    NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

    Published: 6 Feb 2025
    8.1
    High

    CVE-2024-54909

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

    Published: 6 Feb 2025
    6.6
    Medium

    CVE-2024-36557

    Last Modified: 15 Apr 2026

    The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it is possible to hijack the device and control it from the app.

    Published: 6 Feb 2025
    9.8
    Critical

    CVE-2024-36555

    Last Modified: 15 Apr 2026

    Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity of the device.

    Published: 6 Feb 2025
    9.8
    Critical

    CVE-2024-36554

    Last Modified: 15 Apr 2026

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.

    Published: 6 Feb 2025
    8.1
    High

    CVE-2024-36553

    Last Modified: 15 Apr 2026

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

    Published: 6 Feb 2025
    5.3
    Medium

    CVE-2024-25883

    Last Modified: 15 Apr 2026

    The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

    Published: 6 Feb 2025
    6.3
    Medium

    CVE-2020-36085

    Last Modified: 15 Apr 2026

    Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and Last Name in Apply For This Job Form.

    Published: 6 Feb 2025
    7.3
    High

    CVE-2025-23094

    Last Modified: 15 Apr 2026

    The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the same privilege level as the web access process.

    Published: 6 Feb 2025
    9.8
    Critical

    CVE-2022-40916

    Last Modified: 31 Dec 2025

    Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

    Published: 6 Feb 2025
    4.8
    Medium

    CVE-2022-40490

    Last Modified: 31 Dec 2025

    Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

    Published: 6 Feb 2025
    8.8
    High

    CVE-2025-23093

    Last Modified: 15 Apr 2026

    The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.

    Published: 6 Feb 2025
    9.8
    Critical

    CVE-2025-22992

    Last Modified: 30 Jul 2025

    A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.

    Published: 6 Feb 2025
    5.5
    Medium

    CVE-2024-57673

    Last Modified: 23 Apr 2025

    An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

    Published: 6 Feb 2025
    5.5
    Medium

    CVE-2024-57672

    Last Modified: 23 Apr 2025

    An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.

    Published: 6 Feb 2025
    4.5
    Medium

    CVE-2024-57523

    Last Modified: 22 Apr 2025

    Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

    Published: 6 Feb 2025
    9.3
    Critical

    CVE-2024-57428

    Last Modified: 24 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.

    Published: 6 Feb 2025
    4.8
    Medium

    CVE-2024-57599

    Last Modified: 3 Jul 2025

    Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php

    Published: 6 Feb 2025
    8.6
    High

    CVE-2024-57609

    Last Modified: 15 Apr 2026

    An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.

    Published: 6 Feb 2025
    8.8
    High

    CVE-2024-57668

    Last Modified: 23 Oct 2025

    In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

    Published: 6 Feb 2025
    6.3
    Medium

    CVE-2024-48589

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

    Published: 6 Feb 2025
    7.5
    High

    CVE-2024-57610

    Last Modified: 19 Sept 2025

    A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.

    Published: 6 Feb 2025
    5.3
    Medium

    CVE-2024-53586

    Last Modified: 15 Apr 2026

    An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

    Published: 6 Feb 2025
    9.1
    Critical

    CVE-2024-36556

    Last Modified: 15 Apr 2026

    Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.

    Published: 6 Feb 2025
    7.5
    High

    CVE-2024-36558

    Last Modified: 15 Apr 2026

    Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

    Published: 6 Feb 2025
    7.5
    High

    CVE-2024-39033

    Last Modified: 15 Apr 2026

    In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

    Published: 6 Feb 2025
    8.8
    High

    CVE-2024-55241

    Last Modified: 15 Apr 2026

    An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component.

    Published: 6 Feb 2025
    7.5
    High

    CVE-2024-56889

    Last Modified: 18 Apr 2025

    Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

    Published: 6 Feb 2025
    7.5
    High

    CVE-2024-57392

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.

    Published: 6 Feb 2025
    6.1
    Medium

    CVE-2024-57427

    Last Modified: 24 Jun 2025

    PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

    Published: 6 Feb 2025
    5.4
    Medium

    CVE-2024-57429

    Last Modified: 24 Jun 2025

    A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

    Published: 6 Feb 2025
    9.8
    Critical

    CVE-2024-57430

    Last Modified: 24 Jun 2025

    An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

    Published: 6 Feb 2025
    4.3
    Medium

    CVE-2024-49800

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

    Published: 5 Feb 2025
    4.3
    Medium

    CVE-2024-49798

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 5 Feb 2025
    5.9
    Medium

    CVE-2024-49797

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 5 Feb 2025
    5.4
    Medium

    CVE-2024-49796

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

    Published: 5 Feb 2025
    4.3
    Medium

    CVE-2024-49795

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

    Published: 5 Feb 2025
    4.3
    Medium

    CVE-2024-49794

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

    Published: 5 Feb 2025
    9.8
    Critical

    CVE-2025-1066

    Last Modified: 15 Apr 2026

    OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.

    Published: 5 Feb 2025
    5.4
    Medium

    CVE-2024-49793

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 5 Feb 2025
    5.4
    Medium

    CVE-2024-49792

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 5 Feb 2025
    6.4
    Medium

    CVE-2024-49791

    Last Modified: 22 Feb 2025

    IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 5 Feb 2025