CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-53615

    Last Modified: 15 Apr 2026

    A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.

    Published: 30 Jan 2025
    5.7
    Medium

    CVE-2024-55415

    Last Modified: 23 May 2025

    DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

    Published: 30 Jan 2025
    3.5
    Low

    CVE-2024-55416

    Last Modified: 23 May 2025

    DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

    Published: 30 Jan 2025
    6.9
    Medium

    CVE-2025-0844

    Last Modified: 4 Feb 2025

    A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file signup.php of the component Registration Page. The manipulation of the argument firstname/lastname/email/borrow/user_address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 29 Jan 2025
    8.2
    High

    CVE-2025-21396

    Last Modified: 26 Feb 2026

    Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0843

    Last Modified: 16 Apr 2025

    A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unknown function of the file admindashboard.php of the component Admin Panel. The manipulation of the argument email/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    9.9
    Critical

    CVE-2025-21415

    Last Modified: 26 Feb 2026

    Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0842

    Last Modified: 25 Feb 2025

    A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    9.3
    Critical

    CVE-2025-0851

    Last Modified: 15 Apr 2026

    A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0841

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability affects the function loadMore of the component News. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2025-24795

    Last Modified: 31 Jan 2025

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

    Published: 29 Jan 2025
    6.7
    Medium

    CVE-2025-24794

    Last Modified: 31 Jan 2025

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

    Published: 29 Jan 2025
    7
    High

    CVE-2025-24793

    Last Modified: 31 Jan 2025

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

    Published: 29 Jan 2025
    5
    Medium

    CVE-2025-24788

    Last Modified: 31 Jan 2025

    snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This vulnerability affects versions 2.0.12 through 4.2.0 on Linux and macOS. Snowflake fixed the issue in version 4.3.0.

    Published: 29 Jan 2025
    5.1
    Medium

    CVE-2025-24884

    Last Modified: 15 Apr 2026

    kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages. This vulnerability is fixed in 1.0.16.

    Published: 29 Jan 2025
    6.3
    Medium

    CVE-2025-0840

    Last Modified: 4 Mar 2025

    A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.

    Published: 29 Jan 2025
    9.3
    Critical

    CVE-2025-20061

    Last Modified: 15 Apr 2026

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

    Published: 29 Jan 2025
    9.3
    Critical

    CVE-2025-20014

    Last Modified: 15 Apr 2026

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2024-48852

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.

    Published: 29 Jan 2025
    8.8
    High

    CVE-2024-48849

    Last Modified: 15 Apr 2026

    Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.

    Published: 29 Jan 2025
    —
    Unknown

    CVE-2025-0852

    Last Modified: 16 Dec 2025

    Voluntarily withdrawn

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2025-24790

    Last Modified: 12 Feb 2025

    Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching is enabled, the Snowflake JDBC Driver will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 3.6.8 through 3.21.0. Snowflake fixed the issue in version 3.22.0.

    Published: 29 Jan 2025
    7.8
    High

    CVE-2025-24789

    Last Modified: 20 Aug 2025

    Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version. This vulnerability affects versions 3.2.3 through 3.21.0 on Windows. Snowflake fixed the issue in version 3.22.0.

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2025-24791

    Last Modified: 20 Aug 2025

    snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directory. This vulnerability affects versions 1.12.0 through 2.0.1 on Linux. Snowflake fixed the issue in version 2.0.2.

    Published: 29 Jan 2025
    5.9
    Medium

    CVE-2023-35907

    Last Modified: 12 Feb 2025

    IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2023-37413

    Last Modified: 4 Mar 2025

    IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

    Published: 29 Jan 2025
    5.9
    Medium

    CVE-2023-37398

    Last Modified: 12 Feb 2025

    IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2023-37412

    Last Modified: 4 Mar 2025

    IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2025-24792

    Last Modified: 15 Apr 2026

    Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO Driver where executing unsupported queries like PUT or GET on stages causes a signed-to-unsigned conversion error that crashes the application using the Driver. This vulnerability affects versions 0.2.0 through 3.0.3. Snowflake fixed the issue in version 3.1.0.

    Published: 29 Jan 2025
    4.3
    Medium

    CVE-2025-24374

    Last Modified: 15 Apr 2026

    Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

    Published: 29 Jan 2025
    7.1
    High

    CVE-2024-10001

    Last Modified: 5 Sept 2025

    A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To execute the attack, the victim must be logged into GitHub and interact with the attacker controlled malicious webpage containing the hidden iframe. This vulnerability occurs due to an improper sequence of validation, where the origin check occurs after accepting the user-controlled identity property. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.11.16, 3.12.10, 3.13.5, 3.14.2, and 3.15.0. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 29 Jan 2025
    2.1
    Low

    CVE-2024-54462

    Last Modified: 30 Jul 2025

    The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using your app and could potentially override internal files in your app cache. Issue patched in 0.8.12+18. It is recommended to update to the latest version of image_picker_android that contains the changes to address this vulnerability.

    Published: 29 Jan 2025
    2.1
    Low

    CVE-2024-54461

    Last Modified: 30 Jul 2025

    The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select a document file from that provider while using your app and could potentially override internal files in your app cache. Issue patched in 0.5.1+12. It is recommended to update to the latest version of file_selector_android that contains the changes to address this vulnerability.

    Published: 29 Jan 2025
    8.1
    High

    CVE-2024-41140

    Last Modified: 29 Sept 2025

    Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

    Published: 29 Jan 2025
    6.4
    Medium

    CVE-2025-0353

    Last Modified: 21 Apr 2026

    The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jan 2025
    6.4
    Medium

    CVE-2024-13561

    Last Modified: 15 Apr 2026

    The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jan 2025
    8.8
    High

    CVE-2025-0762

    Last Modified: 21 Apr 2025

    Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 29 Jan 2025
    5.9
    Medium

    CVE-2025-0617

    Last Modified: 15 Apr 2026

    An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.

    Published: 29 Jan 2025
    7.5
    High

    CVE-2021-3978

    Last Modified: 29 Jul 2025

    When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation.

    Published: 29 Jan 2025
    8.7
    High

    CVE-2024-7695

    Last Modified: 15 Apr 2026

    Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory outside the bounds of the buffer. Successful exploitation of this vulnerability could result in a denial-of-service attack.

    Published: 29 Jan 2025
    7.2
    High

    CVE-2024-13696

    Last Modified: 15 Apr 2026

    The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter in all versions up to, and including, 1.2.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jan 2025
    6.4
    Medium

    CVE-2025-0804

    Last Modified: 21 Apr 2026

    The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0806

    Last Modified: 12 Feb 2025

    A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0803

    Last Modified: 12 Feb 2025

    A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    6.9
    Medium

    CVE-2025-0802

    Last Modified: 12 Feb 2025

    A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    7.1
    High

    CVE-2024-12749

    Last Modified: 11 May 2025

    The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 29 Jan 2025
    6.1
    Medium

    CVE-2025-23362

    Last Modified: 15 Apr 2026

    The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed on the web browser. Versions 2.3.2 and 2.4.0 were reported as vulnerable. According to the vendor, the product has been refactored after those old versions and the version 3.0.1 is not vulnerable.

    Published: 29 Jan 2025
    5.1
    Medium

    CVE-2025-0800

    Last Modified: 12 Feb 2025

    A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jan 2025
    9.2
    Critical

    CVE-2025-0798

    Last Modified: 9 Oct 2025

    A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    4.4
    Medium

    CVE-2023-33838

    Last Modified: 4 Mar 2025

    IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

    Published: 29 Jan 2025