CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-24478

    Last Modified: 15 Apr 2026

    A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.

    Published: 28 Jan 2025
    8.6
    High

    CVE-2025-22217

    Last Modified: 15 Apr 2026

    Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

    Published: 28 Jan 2025
    5.3
    Medium

    CVE-2025-0783

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

    Published: 28 Jan 2025
    8.7
    High

    CVE-2025-0631

    Last Modified: 15 Apr 2026

    A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.

    Published: 28 Jan 2025
    8.2
    High

    CVE-2024-13484

    Last Modified: 26 Jun 2026

    A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

    Published: 28 Jan 2025
    6.5
    Medium

    CVE-2025-23053

    Last Modified: 16 Apr 2025

    A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

    Published: 28 Jan 2025
    6.5
    Medium

    CVE-2025-23054

    Last Modified: 16 Apr 2025

    A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2025-23057

    Last Modified: 28 Mar 2025

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2025-23056

    Last Modified: 28 Mar 2025

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2025-23055

    Last Modified: 28 Mar 2025

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.

    Published: 28 Jan 2025
    6.2
    Medium

    CVE-2018-9378

    Last Modified: 10 Jul 2025

    In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    8.8
    High

    CVE-2018-9373

    Last Modified: 10 Jul 2025

    In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 28 Jan 2025
    5.7
    Medium

    CVE-2017-13318

    Last Modified: 10 Jul 2025

    In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 28 Jan 2025
    5.7
    Medium

    CVE-2017-13317

    Last Modified: 10 Jul 2025

    In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 28 Jan 2025
    5.4
    Medium

    CVE-2024-8401

    Last Modified: 15 Apr 2026

    CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.

    Published: 28 Jan 2025
    8.6
    High

    CVE-2025-0781

    Last Modified: 6 Aug 2025

    An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.

    Published: 28 Jan 2025
    7.8
    High

    CVE-2025-23385

    Last Modified: 12 Jan 2026

    In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible

    Published: 28 Jan 2025
    6.9
    Medium

    CVE-2025-0432

    Last Modified: 15 Apr 2026

    EWON Flexy 202 transmits user credentials in clear text with no encryption when a user is added, or user credentials are changed via its webpage.

    Published: 28 Jan 2025
    9.3
    Critical

    CVE-2025-24800

    Last Modified: 15 Apr 2026

    Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to steal funds or compromise other kinds of cross-chain applications. This vulnerability is fixed in 15.0.1.

    Published: 28 Jan 2025
    8.7
    High

    CVE-2025-23213

    Last Modified: 8 May 2025

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.

    Published: 28 Jan 2025
    7.7
    High

    CVE-2025-23212

    Last Modified: 8 May 2025

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.

    Published: 28 Jan 2025
    9.9
    Critical

    CVE-2025-23211

    Last Modified: 8 May 2025

    Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

    Published: 28 Jan 2025
    8.7
    High

    CVE-2025-23045

    Last Modified: 16 Sept 2025

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT deployments that run any of the serverless functions of type tracker from the CVAT Git repository, namely TransT and SiamMask. Deployments with custom functions of type tracker may also be affected, depending on how they handle state serialization. If a function uses an unsafe serialization library such as pickle or jsonpickle, it's likely to be vulnerable. Upgrade to CVAT 2.26.0 or later. If you are unable to upgrade, shut down any instances of the TransT or SiamMask functions you're running.

    Published: 28 Jan 2025
    7
    High

    CVE-2025-0659

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.

    Published: 28 Jan 2025
    5.1
    Medium

    CVE-2024-7881

    Last Modified: 18 Dec 2025

    An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.

    Published: 28 Jan 2025
    4.3
    Medium

    CVE-2024-6351

    Last Modified: 15 Apr 2026

    A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

    Published: 28 Jan 2025
    5.1
    Medium

    CVE-2024-11956

    Last Modified: 4 Nov 2025

    A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 28 Jan 2025
    5.1
    Medium

    CVE-2024-11954

    Last Modified: 4 Nov 2025

    A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Jan 2025
    7.8
    High

    CVE-2025-0065

    Last Modified: 15 Apr 2026

    Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a Windows system to elevate privileges via argument injection.

    Published: 28 Jan 2025
    6.5
    Medium

    CVE-2024-23953

    Last Modified: 15 Jul 2025

    Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are recommended to upgrade to version 4.0.0, which fixes this issue. The problem occurs when an application doesn’t use a constant-time algorithm for validating a signature. The method Arrays.equals() returns false right away when it sees that one of the input’s bytes are different. It means that the comparison time depends on the contents of the arrays. This little thing may allow an attacker to forge a valid signature for an arbitrary message byte by byte. So it might allow malicious users to submit splits/work with selected signatures to LLAP without running as a privileged user, potentially leading to DDoS attack. More details in the reference section.

    Published: 28 Jan 2025
    4.3
    Medium

    CVE-2025-0290

    Last Modified: 5 Aug 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.0 prior to 17.5.5, from 17.6 prior to 17.6.3, and from 17.7 prior to 17.7.1. Under certain conditions, processing of CI artifacts metadata could cause background jobs to become unresponsive.

    Published: 28 Jan 2025
    6.4
    Medium

    CVE-2024-13527

    Last Modified: 8 Apr 2026

    The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jan 2025
    6.1
    Medium

    CVE-2024-13521

    Last Modified: 8 Apr 2026

    The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the mas_options function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 28 Jan 2025
    6.4
    Medium

    CVE-2025-0321

    Last Modified: 8 Apr 2026

    The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 28 Jan 2025
    7.2
    High

    CVE-2024-13509

    Last Modified: 8 Apr 2026

    The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and including, 1.10.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability is partially fixed in 1.10.13 and completely fixed in 1.10.14.

    Published: 28 Jan 2025
    9.8
    Critical

    CVE-2024-13448

    Last Modified: 8 Apr 2026

    The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 28 Jan 2025
    4.8
    Medium

    CVE-2025-24810

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2025-23084

    Last Modified: 4 Nov 2025

    A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path that does not start with the file separator is treated as relative to the current directory. This vulnerability affects Windows users of `path.join` API.

    Published: 28 Jan 2025
    7.5
    High

    CVE-2024-11135

    Last Modified: 8 Apr 2026

    The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2024-53881

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm on the host, which may lead to denial of service.

    Published: 28 Jan 2025
    7.8
    High

    CVE-2024-0146

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2024-53869

    Last Modified: 15 Apr 2026

    NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 28 Jan 2025
    3.3
    Low

    CVE-2024-0149

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might lead to limited information disclosure.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2024-0147

    Last Modified: 15 Apr 2026

    NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denial of service or data tampering.

    Published: 28 Jan 2025
    7.1
    High

    CVE-2024-0150

    Last Modified: 15 Apr 2026

    NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before the beginning of a buffer. A successful exploit of this vulnerability might lead to information disclosure, denial of service, or data tampering.

    Published: 28 Jan 2025
    6.8
    Medium

    CVE-2024-0140

    Last Modified: 15 Apr 2026

    NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data issue. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

    Published: 28 Jan 2025
    5.5
    Medium

    CVE-2024-0137

    Last Modified: 6 Oct 2025

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to denial of service and escalation of privileges.

    Published: 28 Jan 2025
    7.6
    High

    CVE-2024-0136

    Last Modified: 6 Oct 2025

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 28 Jan 2025
    7.6
    High

    CVE-2024-0135

    Last Modified: 6 Oct 2025

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 28 Jan 2025
    4.8
    Medium

    CVE-2024-12807

    Last Modified: 11 May 2025

    The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 28 Jan 2025