CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2024-13347

    Last Modified: 18 Apr 2025

    The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

    Published: 3 Feb 2025
    1.3
    Low

    CVE-2025-0974

    Last Modified: 20 Apr 2026

    A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.45 is capable of addressing this issue. Upgrading the affected component is advised.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2025-0973

    Last Modified: 28 Feb 2025

    A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument select[] leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2025-0972

    Last Modified: 10 Oct 2025

    A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. The manipulation of the argument subject leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 25.01.22.245a473c54 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2025-22918

    Last Modified: 15 Apr 2026

    Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2024-56901

    Last Modified: 15 Apr 2026

    A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2024-56898

    Last Modified: 15 Apr 2026

    Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-56902

    Last Modified: 15 Apr 2026

    Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-44449

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-34897

    Last Modified: 15 Apr 2026

    Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-34896

    Last Modified: 15 Apr 2026

    An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.

    Published: 3 Feb 2025
    5.1
    Medium

    CVE-2023-52164

    Last Modified: 15 Apr 2026

    access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-57004

    Last Modified: 22 Dec 2025

    Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2025-25065

    Last Modified: 11 Jun 2025

    SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2025-25064

    Last Modified: 26 Feb 2026

    SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in the request, allowing them to inject arbitrary SQL queries that could retrieve email metadata.

    Published: 3 Feb 2025
    4.4
    Medium

    CVE-2025-25063

    Last Modified: 23 Jan 2026

    An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it is possible to execute scripting in the browser when an SVG image is viewed. This issue is mitigated by the attacker needing to be able to upload SVG images, and that Backdrop embeds all uploaded SVG images within &lt;img&gt; tags, which prevents scripting from executing. The SVG must be viewed directly by its URL in order to run any embedded scripting.

    Published: 3 Feb 2025
    9.8
    Critical

    CVE-2025-22978

    Last Modified: 17 Mar 2026

    eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.

    Published: 3 Feb 2025
    5.8
    Medium

    CVE-2025-25181

    Last Modified: 26 Feb 2026

    A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

    Published: 3 Feb 2025
    5
    Medium

    CVE-2024-57966

    Last Modified: 15 Apr 2026

    libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

    Published: 3 Feb 2025
    9.9
    Critical

    CVE-2024-57968

    Last Modified: 4 Nov 2025

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

    Published: 3 Feb 2025
    4.2
    Medium

    CVE-2024-54840

    Last Modified: 14 Mar 2025

    PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.

    Published: 3 Feb 2025
    9.8
    Critical

    CVE-2024-57099

    Last Modified: 13 May 2025

    ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

    Published: 3 Feb 2025
    5.4
    Medium

    CVE-2024-57175

    Last Modified: 28 Mar 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

    Published: 3 Feb 2025
    6.3
    Medium

    CVE-2024-57237

    Last Modified: 15 Apr 2026

    Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code.

    Published: 3 Feb 2025
    6.4
    Medium

    CVE-2024-57522

    Last Modified: 22 Apr 2025

    SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.

    Published: 3 Feb 2025
    4.2
    Medium

    CVE-2024-57967

    Last Modified: 15 Apr 2026

    PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2024-36437

    Last Modified: 15 Apr 2026

    The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.

    Published: 3 Feb 2025
    4.4
    Medium

    CVE-2025-25062

    Last Modified: 23 Jan 2026

    An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2023-52163

    Last Modified: 26 Feb 2026

    Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 3 Feb 2025
    8.1
    High

    CVE-2025-25066

    Last Modified: 2 Oct 2025

    nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-50656

    Last Modified: 19 Mar 2025

    itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

    Published: 3 Feb 2025
    4.8
    Medium

    CVE-2024-53942

    Last Modified: 15 Apr 2026

    An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via crafted input.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-53943

    Last Modified: 15 Apr 2026

    An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute JavaScript within the context of the current user by injecting JavaScript into the SSID field. If an administrator logs into the device, the injected script runs in their browser, executing the malicious payload.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2024-55456

    Last Modified: 15 Apr 2025

    lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

    Published: 3 Feb 2025
    8.1
    High

    CVE-2024-56903

    Last Modified: 15 Apr 2026

    Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-56921

    Last Modified: 22 Apr 2025

    An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2024-56946

    Last Modified: 24 Jun 2025

    Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the server from accepting new DNS-over-QUIC connections by triggering unhandled exceptions in listener threads.

    Published: 3 Feb 2025
    4.8
    Medium

    CVE-2024-57097

    Last Modified: 13 May 2025

    ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.

    Published: 3 Feb 2025
    9.8
    Critical

    CVE-2024-57098

    Last Modified: 2 Oct 2025

    Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

    Published: 3 Feb 2025
    7.3
    High

    CVE-2024-57238

    Last Modified: 15 Apr 2026

    Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.

    Published: 3 Feb 2025
    9.8
    Critical

    CVE-2024-57450

    Last Modified: 13 May 2025

    ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-57451

    Last Modified: 13 May 2025

    ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-57452

    Last Modified: 13 May 2025

    ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

    Published: 3 Feb 2025
    4.8
    Medium

    CVE-2024-57498

    Last Modified: 13 Jun 2025

    Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-57669

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2025-0971

    Last Modified: 10 Oct 2025

    A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Account/EditProfile of the component Profile Editing. The manipulation of the argument username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 25.01.22.245a473c54 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 2 Feb 2025
    6.9
    Medium

    CVE-2025-0970

    Last Modified: 10 Oct 2025

    A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /Account/Login. The manipulation of the argument ReturnUrl leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 25.01.22.245a473c54 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 2 Feb 2025
    5.3
    Medium

    CVE-2025-0967

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/add_chatroom.php. The manipulation of the argument chatname/chatpass leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Feb 2025
    4.4
    Medium

    CVE-2024-0131

    Last Modified: 15 Apr 2026

    NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read  a buffer with an incorrect length. A successful exploit of this vulnerability might lead to denial of service.

    Published: 2 Feb 2025
    5.1
    Medium

    CVE-2025-0961

    Last Modified: 28 May 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Job Recruitment 1.0. Affected by this issue is some unknown functionality of the file /_parse/load_job-details.php. The manipulation of the argument business_stream_name/company_website_url leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Feb 2025