CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-23963

    Last Modified: 12 Aug 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the PBAP_DecodeVCARD function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2024-23962

    Last Modified: 12 Aug 2025

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device.

    Published: 30 Jan 2025
    2.6
    Low

    CVE-2023-6195

    Last Modified: 5 Aug 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image value when importing a GitHub repository.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2024-23971

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.

    Published: 30 Jan 2025
    6.5
    Medium

    CVE-2024-23970

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2024-23969

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2024-23968

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2024-23973

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the handling of HTTP GET requests. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.

    Published: 30 Jan 2025
    7.5
    High

    CVE-2024-24731

    Last Modified: 30 Sept 2025

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the http_download command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device.

    Published: 30 Jan 2025
    7.6
    High

    CVE-2025-24885

    Last Modified: 15 Apr 2026

    pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.

    Published: 30 Jan 2025
    7.7
    High

    CVE-2025-24886

    Last Modified: 15 Apr 2026

    pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website.

    Published: 30 Jan 2025
    —
    Unknown

    CVE-2024-13817

    Last Modified: 31 Jan 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-0882

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/addnewmember.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-0881

    Last Modified: 23 Apr 2025

    A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. The manipulation of the argument rname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-0880

    Last Modified: 25 Feb 2025

    A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The manipulation of the argument planid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jan 2025
    7.5
    High

    CVE-2025-0574

    Last Modified: 19 Feb 2025

    Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of URLs in the web server module. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-25318.

    Published: 30 Jan 2025
    4.3
    Medium

    CVE-2025-0572

    Last Modified: 19 Feb 2025

    Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to write files in the context of the current user. Was ZDI-CAN-25308.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-0573

    Last Modified: 19 Feb 2025

    Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to write files in the context of the current user. Was ZDI-CAN-25309.

    Published: 30 Jan 2025
    7.5
    High

    CVE-2025-0569

    Last Modified: 19 Feb 2025

    Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-25303.

    Published: 30 Jan 2025
    6.5
    Medium

    CVE-2025-0571

    Last Modified: 19 Feb 2025

    Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-25305.

    Published: 30 Jan 2025
    6.5
    Medium

    CVE-2025-0570

    Last Modified: 19 Feb 2025

    Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-25304.

    Published: 30 Jan 2025
    7.5
    High

    CVE-2025-0568

    Last Modified: 19 Feb 2025

    Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-25302.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2025-0147

    Last Modified: 1 Aug 2025

    Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.

    Published: 30 Jan 2025
    3.9
    Low

    CVE-2025-0146

    Last Modified: 1 Aug 2025

    Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via local access.

    Published: 30 Jan 2025
    4.6
    Medium

    CVE-2025-0145

    Last Modified: 20 Aug 2025

    Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.

    Published: 30 Jan 2025
    6.4
    Medium

    CVE-2024-1211

    Last Modified: 5 Aug 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth provider.

    Published: 30 Jan 2025
    3.1
    Low

    CVE-2025-0144

    Last Modified: 20 Aug 2025

    Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network access.

    Published: 30 Jan 2025
    4.3
    Medium

    CVE-2025-0143

    Last Modified: 31 Jul 2025

    Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a denial of service via network access.

    Published: 30 Jan 2025
    4.3
    Medium

    CVE-2025-0142

    Last Modified: 15 Apr 2026

    Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.

    Published: 30 Jan 2025
    8.6
    High

    CVE-2025-24802

    Last Modified: 15 Apr 2026

    Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) always include the 0 -> 0 input-output pair. Thus a malicious prover can always prove that f(0) = 0 for any lookup table f (unless its length happens to be divisible by 26). The cause of problem is that the LookupTableGate-s are padded with zeros. A workaround from the user side is to extend the table (by repeating some entries) so that its length becomes divisible by 26. This vulnerability is fixed in 1.0.1.

    Published: 30 Jan 2025
    6.9
    Medium

    CVE-2025-0681

    Last Modified: 15 Apr 2026

    The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.

    Published: 30 Jan 2025
    9.3
    Critical

    CVE-2025-0680

    Last Modified: 15 Apr 2026

    Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

    Published: 30 Jan 2025
    7.8
    High

    CVE-2024-44142

    Last Modified: 2 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.

    Published: 30 Jan 2025
    8.9
    High

    CVE-2025-24507

    Last Modified: 15 Apr 2026

    This vulnerability allows appliance compromise at boot time.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-24506

    Last Modified: 15 Apr 2026

    A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.

    Published: 30 Jan 2025
    8.8
    High

    CVE-2025-24505

    Last Modified: 15 Apr 2026

    This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-24504

    Last Modified: 15 Apr 2026

    An improper input validation the CSRF filter results in unsanitized user input written to the application logs.

    Published: 30 Jan 2025
    9.3
    Critical

    CVE-2025-24503

    Last Modified: 15 Apr 2026

    A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-24502

    Last Modified: 15 Apr 2026

    An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-24501

    Last Modified: 15 Apr 2026

    An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.

    Published: 30 Jan 2025
    8.2
    High

    CVE-2025-0683

    Last Modified: 15 Apr 2026

    In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.

    Published: 30 Jan 2025
    7.7
    High

    CVE-2025-0626

    Last Modified: 15 Apr 2026

    The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by attempting to update the device from the user menu. This could serve as a backdoor to the device, and could lead to a malicious actor being able to upload and overwrite files on the device.

    Published: 30 Jan 2025
    9.3
    Critical

    CVE-2024-12248

    Last Modified: 15 Apr 2026

    Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.

    Published: 30 Jan 2025
    8.7
    High

    CVE-2025-24500

    Last Modified: 15 Apr 2026

    The vulnerability allows an unauthenticated attacker to access information in PAM database.

    Published: 30 Jan 2025
    5.3
    Medium

    CVE-2025-0874

    Last Modified: 23 Oct 2025

    A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management 1.0. Affected by this issue is some unknown functionality of the file /admin/approve.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jan 2025
    9.3
    Critical

    CVE-2025-0477

    Last Modified: 4 Nov 2025

    An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.

    Published: 30 Jan 2025
    8.5
    High

    CVE-2023-29080

    Last Modified: 15 Apr 2026

    Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.

    Published: 30 Jan 2025
    7.3
    High

    CVE-2025-0497

    Last Modified: 4 Nov 2025

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.

    Published: 30 Jan 2025
    7
    High

    CVE-2025-0498

    Last Modified: 4 Nov 2025

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.

    Published: 30 Jan 2025
    8.5
    High

    CVE-2024-2658

    Last Modified: 15 Apr 2026

    A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

    Published: 30 Jan 2025