CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-57581

    Last Modified: 18 Mar 2025

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2024-57583

    Last Modified: 4 Feb 2025

    Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

    Published: 16 Jan 2025
    3.5
    Low

    CVE-2024-57611

    Last Modified: 15 Apr 2025

    07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2024-57676

    Last Modified: 2 May 2025

    An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2024-57678

    Last Modified: 2 May 2025

    An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

    Published: 16 Jan 2025
    5.3
    Medium

    CVE-2024-57680

    Last Modified: 2 May 2025

    An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.

    Published: 16 Jan 2025
    5.3
    Medium

    CVE-2024-57681

    Last Modified: 2 May 2025

    An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2024-57682

    Last Modified: 2 May 2025

    An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2024-57684

    Last Modified: 2 May 2025

    An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2024-57703

    Last Modified: 17 Mar 2025

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2024-57704

    Last Modified: 17 Mar 2025

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2024-57768

    Last Modified: 28 May 2025

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2024-57769

    Last Modified: 23 Jan 2025

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2024-57770

    Last Modified: 23 Jan 2025

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.

    Published: 16 Jan 2025
    4.8
    Medium

    CVE-2024-57771

    Last Modified: 17 May 2025

    A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 16 Jan 2025
    4.8
    Medium

    CVE-2024-57773

    Last Modified: 17 May 2025

    A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 16 Jan 2025
    4.8
    Medium

    CVE-2024-57774

    Last Modified: 17 May 2025

    A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 16 Jan 2025
    8.8
    High

    CVE-2024-57775

    Last Modified: 31 Jan 2025

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.

    Published: 16 Jan 2025
    4.6
    Medium

    CVE-2024-57776

    Last Modified: 17 May 2025

    A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2025-22905

    Last Modified: 9 Apr 2025

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2025-22904

    Last Modified: 9 Apr 2025

    RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

    Published: 16 Jan 2025
    9.8
    Critical

    CVE-2025-22907

    Last Modified: 9 Apr 2025

    RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-0476

    Last Modified: 24 Sept 2025

    Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment

    Published: 15 Jan 2025
    6.1
    Medium

    CVE-2025-0215

    Last Modified: 22 Apr 2026

    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an admin user into performing an action such as clicking on a link.

    Published: 15 Jan 2025
    8.7
    High

    CVE-2025-0492

    Last Modified: 24 Sept 2025

    A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0491

    Last Modified: 27 Feb 2025

    A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0490

    Last Modified: 5 May 2025

    A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects some unknown processing of the file /fladmin/article_dodel.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0489

    Last Modified: 5 May 2025

    A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown code of the file /fladmin/friendlink_dodel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0488

    Last Modified: 5 May 2025

    A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0487

    Last Modified: 12 Jul 2025

    A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /fladmin/cat_edit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    6.9
    Medium

    CVE-2025-0486

    Last Modified: 13 Jul 2025

    A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fladmin/login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0485

    Last Modified: 12 Jul 2025

    A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown function of the file /fladmin/sysconfig_doedit.php. The manipulation of the argument info leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    6.9
    Medium

    CVE-2025-0484

    Last Modified: 12 Jul 2025

    A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin/sysconfig_doedit.php of the component Backend. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    9.1
    Critical

    CVE-2025-22146

    Last Modified: 15 Apr 2026

    Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. The Sentry SaaS fix was deployed on Jan 14, 2025. For self hosted users; if only a single organization is allowed `(SENTRY_SINGLE_ORGANIZATION = True)`, then no action is needed. Otherwise, users should upgrade to version 25.1.0 or higher. There are no known workarounds for this vulnerability.

    Published: 15 Jan 2025
    4.6
    Medium

    CVE-2024-54470

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.

    Published: 15 Jan 2025
    4.3
    Medium

    CVE-2024-54535

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.

    Published: 15 Jan 2025
    5.5
    Medium

    CVE-2024-40854

    Last Modified: 2 Apr 2026

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpected system termination.

    Published: 15 Jan 2025
    2.4
    Low

    CVE-2024-40839

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.

    Published: 15 Jan 2025
    7.8
    High

    CVE-2024-40771

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 15 Jan 2025
    7.8
    High

    CVE-2024-27856

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.

    Published: 15 Jan 2025
    4.6
    Medium

    CVE-2024-44136

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.

    Published: 15 Jan 2025
    4.3
    Medium

    CVE-2024-54540

    Last Modified: 2 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0483

    Last Modified: 13 May 2025

    A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects unknown code of the file /fladmin/jump.php. The manipulation of the argument message/error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    6.9
    Medium

    CVE-2025-0482

    Last Modified: 29 Apr 2025

    A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    6.9
    Medium

    CVE-2025-0481

    Last Modified: 16 Jul 2025

    A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025
    7.7
    High

    CVE-2025-0501

    Last Modified: 15 Apr 2026

    An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.

    Published: 15 Jan 2025
    7.7
    High

    CVE-2025-0500

    Last Modified: 15 Apr 2026

    An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

    Published: 15 Jan 2025
    6.9
    Medium

    CVE-2025-0502

    Last Modified: 15 Dec 2025

    Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.

    Published: 15 Jan 2025
    7.5
    High

    CVE-2024-52005

    Last Modified: 18 Dec 2025

    Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

    Published: 15 Jan 2025
    5.3
    Medium

    CVE-2025-0480

    Last Modified: 13 May 2025

    A vulnerability classified as problematic has been found in wuzhicms 4.1.0. This affects the function test of the file coreframe/app/search/admin/config.php. The manipulation of the argument sphinxhost/sphinxport leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Jan 2025