CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2025-0797

    Last Modified: 9 Oct 2025

    A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /var/Microworld/ of the component Quarantine Handler. The manipulation leads to incorrect default permissions. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2025-0795

    Last Modified: 13 May 2025

    A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation of the argument flowId leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2025-0794

    Last Modified: 13 May 2025

    A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2025-0793

    Last Modified: 13 May 2025

    A vulnerability has been found in ESAFENET CDG V5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /todoDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2025-0792

    Last Modified: 23 May 2025

    A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2025
    5.9
    Medium

    CVE-2023-35017

    Last Modified: 4 Mar 2025

    IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.

    Published: 29 Jan 2025
    7.8
    High

    CVE-2024-57509

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions.

    Published: 29 Jan 2025
    8
    High

    CVE-2025-24527

    Last Modified: 15 Apr 2026

    An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.

    Published: 29 Jan 2025
    9.8
    Critical

    CVE-2024-57665

    Last Modified: 23 May 2025

    JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.

    Published: 29 Jan 2025
    6.5
    Medium

    CVE-2024-57513

    Last Modified: 15 Apr 2026

    A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.

    Published: 29 Jan 2025
    9.8
    Critical

    CVE-2024-54852

    Last Modified: 24 May 2025

    When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user input, an unauthenticated attacker is then able to perform various malicious actions, such as creating arbitrary accounts and spraying passwords.

    Published: 29 Jan 2025
    7.5
    High

    CVE-2024-23733

    Last Modified: 15 Apr 2026

    The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin/#/login/ URI.

    Published: 29 Jan 2025
    7.5
    High

    CVE-2024-11187

    Last Modified: 15 Apr 2026

    It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.

    Published: 29 Jan 2025
    0
    Low

    CVE-2024-57965

    Last Modified: 19 Sept 2025

    In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

    Published: 29 Jan 2025
    8.8
    High

    CVE-2024-48761

    Last Modified: 23 May 2025

    Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

    Published: 29 Jan 2025
    6.1
    Medium

    CVE-2024-51182

    Last Modified: 23 May 2025

    HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter.

    Published: 29 Jan 2025
    8.8
    High

    CVE-2024-54851

    Last Modified: 23 May 2025

    Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

    Published: 29 Jan 2025
    9.8
    Critical

    CVE-2024-57395

    Last Modified: 15 Apr 2026

    Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters.

    Published: 29 Jan 2025
    7.2
    High

    CVE-2024-57436

    Last Modified: 14 May 2025

    RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.

    Published: 29 Jan 2025
    6.5
    Medium

    CVE-2024-57437

    Last Modified: 14 May 2025

    RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.

    Published: 29 Jan 2025
    5.4
    Medium

    CVE-2024-57438

    Last Modified: 14 May 2025

    Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

    Published: 29 Jan 2025
    4.9
    Medium

    CVE-2024-57439

    Last Modified: 14 May 2025

    An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.

    Published: 29 Jan 2025
    7.8
    High

    CVE-2024-57510

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.

    Published: 29 Jan 2025
    5.3
    Medium

    CVE-2025-0791

    Last Modified: 23 May 2025

    A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0790

    Last Modified: 23 May 2025

    A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0789

    Last Modified: 23 May 2025

    A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0788

    Last Modified: 16 May 2025

    A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /content_top.jsp. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0787

    Last Modified: 16 May 2025

    A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /appDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0786

    Last Modified: 16 May 2025

    A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2024-29869

    Last Modified: 15 Jul 2025

    Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0785

    Last Modified: 16 May 2025

    A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. The manipulation of the argument help leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2025
    7
    High

    CVE-2025-24482

    Last Modified: 15 Apr 2026

    A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.

    Published: 28 Jan 2025
    7
    High

    CVE-2025-24481

    Last Modified: 15 Apr 2026

    An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.

    Published: 28 Jan 2025
    6.7
    Medium

    CVE-2025-24826

    Last Modified: 15 Apr 2026

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4625.

    Published: 28 Jan 2025
    6.3
    Medium

    CVE-2025-0784

    Last Modified: 20 Aug 2025

    A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40677

    Last Modified: 22 Apr 2025

    In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    7.7
    High

    CVE-2024-40676

    Last Modified: 22 Apr 2025

    In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    7.5
    High

    CVE-2024-40675

    Last Modified: 22 Apr 2025

    In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2024-40674

    Last Modified: 22 Apr 2025

    In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    6.5
    Medium

    CVE-2024-40673

    Last Modified: 18 Apr 2025

    In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40672

    Last Modified: 18 Apr 2025

    In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40670

    Last Modified: 27 Jun 2025

    In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40669

    Last Modified: 27 Jun 2025

    In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40651

    Last Modified: 27 Jun 2025

    In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-40649

    Last Modified: 27 Jun 2025

    In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-34748

    Last Modified: 27 Jun 2025

    In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-34733

    Last Modified: 27 Jun 2025

    In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.4
    High

    CVE-2024-34732

    Last Modified: 27 Jun 2025

    In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    9.3
    Critical

    CVE-2025-24480

    Last Modified: 15 Apr 2026

    A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.

    Published: 28 Jan 2025
    8.6
    High

    CVE-2025-24479

    Last Modified: 15 Apr 2026

    A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.

    Published: 28 Jan 2025