CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-5743

    Last Modified: 15 Apr 2026

    An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42.

    Published: 13 Jan 2025
    4.3
    Medium

    CVE-2024-6352

    Last Modified: 15 Apr 2026

    A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

    Published: 13 Jan 2025
    5.4
    Medium

    CVE-2024-12211

    Last Modified: 29 Oct 2025

    Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

    Published: 13 Jan 2025
    8.4
    High

    CVE-2024-52333

    Last Modified: 3 Nov 2025

    An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 13 Jan 2025
    8.4
    High

    CVE-2024-47796

    Last Modified: 3 Nov 2025

    An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 13 Jan 2025
    4.9
    Medium

    CVE-2024-11736

    Last Modified: 31 Aug 2026

    A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2024-56065

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Reflected XSS.This issue affects WP2LEADS: from n/a through <= 3.4.2.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2024-56301

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Reflected XSS.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.21.

    Published: 13 Jan 2025
    4.3
    Medium

    CVE-2025-22800

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22314

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Scripts Food Store – Online Food Delivery & Pickup food-store allows Reflected XSS.This issue affects Food Store – Online Food Delivery & Pickup: from n/a through <= 1.5.4.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22337

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin Order Audit Log for WooCommerce order-audit-log-for-woocommerce allows Reflected XSS.This issue affects Order Audit Log for WooCommerce: from n/a through <= 2.0.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22344

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in timmcdaniels Media Category Library media-category-library allows Reflected XSS.This issue affects Media Category Library: from n/a through <= 2.7.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22498

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS lucidlms allows Reflected XSS.This issue affects LucidLMS: from n/a through <= 1.0.5.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22499

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Post Tree f4-tree allows Reflected XSS.This issue affects F4 Post Tree: from n/a through <= 1.1.18.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22506

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.7.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22514

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja KNR Author List Widget knr-author-list-widget allows Reflected XSS.This issue affects KNR Author List Widget: from n/a through <= 3.1.1.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22567

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer trustist-reviewer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through <= 2.0.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22568

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Post And Page Reactions post-and-page-reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through <= 1.0.5.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22569

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GrandSlambert Featured Page Widget featured-page-widget allows Reflected XSS.This issue affects Featured Page Widget: from n/a through <= 2.2.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22570

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdjekic Inline Tweets inline-tweets allows Stored XSS.This issue affects Inline Tweets: from n/a through <= 2.0.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22576

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Downing Site PIN site-pin allows Reflected XSS.This issue affects Site PIN: from n/a through <= 1.3.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22583

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anshulsojatia Scan External Links scan-external-links allows Reflected XSS.This issue affects Scan External Links: from n/a through <= 1.0.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22586

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dstoever WPEX Replace DB Urls wpex-replace allows Reflected XSS.This issue affects WPEX Replace DB Urls: from n/a through <= 0.4.0.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2025-22588

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligence_lab Scanventory woocommerce-inventory-management allows Reflected XSS.This issue affects Scanventory: from n/a through <= 1.1.3.

    Published: 13 Jan 2025
    9.8
    Critical

    CVE-2025-22777

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects GiveWP: from n/a through <= 3.19.3.

    Published: 13 Jan 2025
    4.3
    Medium

    CVE-2025-22828

    Last Modified: 1 Jul 2025

    CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources.  An attacker with a user-account and access or prior knowledge of resource UUIDs may exploit this issue to read contents of the comments (annotations) or add malicious comments (annotations) to such resources.  This may cause potential loss of confidentiality of CloudStack environments and resources if the comments (annotations) contain any privileged information. However, guessing or brute-forcing resource UUIDs are generally hard to impossible and access to listing or adding comments isn't same as access to CloudStack resources, making this issue of very low severity and general low impact. CloudStack admins may also disallow listAnnotations and addAnnotation API access to non-admin roles in their environment as an interim measure.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2024-11734

    Last Modified: 31 Aug 2026

    A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

    Published: 13 Jan 2025
    7.8
    High

    CVE-2024-52938

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    6.7
    Medium

    CVE-2024-52937

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    4.4
    Medium

    CVE-2024-52936

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    4.1
    Medium

    CVE-2024-52935

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2024-47895

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    7.1
    High

    CVE-2024-47894

    Last Modified: 15 Apr 2026

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

    Published: 13 Jan 2025
    8.8
    High

    CVE-2024-47897

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls resulting in platform instability and reboots.

    Published: 13 Jan 2025
    7.8
    High

    CVE-2025-0412

    Last Modified: 7 Aug 2025

    Luxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of KSP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22139.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0410

    Last Modified: 5 May 2025

    A vulnerability classified as critical was found in liujianview gymxmjpa 1.0. This vulnerability affects the function MenberDaoInpl of the file src/main/java/com/liujian/gymxmjpa/controller/MenberConntroller.java. The manipulation of the argument hyname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0409

    Last Modified: 5 May 2025

    A vulnerability classified as critical has been found in liujianview gymxmjpa 1.0. This affects the function MembertypeDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/MembertypeController.java. The manipulation of the argument typeName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0408

    Last Modified: 5 May 2025

    A vulnerability was found in liujianview gymxmjpa 1.0. It has been rated as critical. Affected by this issue is the function LoosDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/LoosController.java. The manipulation of the argument loosName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    4.8
    Medium

    CVE-2024-12568

    Last Modified: 8 May 2025

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 13 Jan 2025
    4.8
    Medium

    CVE-2024-12567

    Last Modified: 8 May 2025

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 13 Jan 2025
    4.8
    Medium

    CVE-2024-12566

    Last Modified: 8 May 2025

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 13 Jan 2025
    7.5
    High

    CVE-2024-12274

    Last Modified: 27 Aug 2025

    The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

    Published: 13 Jan 2025
    4.8
    Medium

    CVE-2024-11636

    Last Modified: 8 May 2025

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0407

    Last Modified: 5 May 2025

    A vulnerability was found in liujianview gymxmjpa 1.0. It has been declared as critical. Affected by this vulnerability is the function EquipmentDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/EquipmentController.java. The manipulation of the argument hyname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0406

    Last Modified: 5 May 2025

    A vulnerability was found in liujianview gymxmjpa 1.0. It has been classified as critical. Affected is the function SubjectDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/SubjectController.java. The manipulation of the argument subname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0405

    Last Modified: 5 May 2025

    A vulnerability was found in liujianview gymxmjpa 1.0 and classified as critical. This issue affects the function GoodsDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/GoodsController.java. The manipulation of the argument goodsName leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2025-0404

    Last Modified: 15 Apr 2026

    A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the function CoachController of the file src/main/java/com/liujian/gymxmjpa/controller/CoachController.java. The manipulation of the argument coachName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    6.9
    Medium

    CVE-2025-0403

    Last Modified: 21 Oct 2025

    A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is some unknown functionality of the file /user/sendMsg of the component Phone Number Validation Handler. The manipulation of the argument code leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Jan 2025
    5.3
    Medium

    CVE-2024-46919

    Last Modified: 20 Jun 2025

    An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.

    Published: 13 Jan 2025
    6.5
    Medium

    CVE-2024-46920

    Last Modified: 20 Jun 2025

    An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadInputBuffers.

    Published: 13 Jan 2025