CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2025-22621

    Last Modified: 15 Apr 2026

    In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2024-56270

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data.This issue affects WP SecureSubmit: from n/a through <= 1.5.20.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2024-56272

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2025-0299

    Last Modified: 7 Apr 2025

    A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jan 2025
    7.3
    High

    CVE-2024-12430

    Last Modified: 15 Apr 2026

    An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into a specifically crafted file, which then will be executed by root user. All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.

    Published: 7 Jan 2025
    7.5
    High

    CVE-2024-40749

    Last Modified: 4 Jun 2025

    Improper Access Controls allows access to protected views.

    Published: 7 Jan 2025
    6.1
    Medium

    CVE-2024-40747

    Last Modified: 4 Jun 2025

    Various module chromes didn't properly process inputs, leading to XSS vectors.

    Published: 7 Jan 2025
    7.5
    High

    CVE-2024-40748

    Last Modified: 4 Jun 2025

    Lack of output escaping in the id attribute of menu lists.

    Published: 7 Jan 2025
    7.5
    High

    CVE-2024-8361

    Last Modified: 15 Apr 2026

    In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device will restart after watch dog expires. If watchdog is not implemented, device can be recovered only after a hard reset

    Published: 7 Jan 2025
    5.1
    Medium

    CVE-2025-0243

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-0242

    Last Modified: 21 Apr 2026

    Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    9.8
    Critical

    CVE-2025-0247

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.

    Published: 7 Jan 2025
    4
    Medium

    CVE-2025-0240

    Last Modified: 20 Apr 2026

    Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2025-0238

    Last Modified: 20 Apr 2026

    Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    7.7
    High

    CVE-2025-0241

    Last Modified: 21 Apr 2026

    When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    4
    Medium

    CVE-2025-0239

    Last Modified: 21 Apr 2026

    When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-0246

    Last Modified: 20 Apr 2026

    When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability was fixed in Firefox 134.

    Published: 7 Jan 2025
    3.3
    Low

    CVE-2025-0245

    Last Modified: 20 Apr 2026

    Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox 134.

    Published: 7 Jan 2025
    5.4
    Medium

    CVE-2025-0237

    Last Modified: 20 Apr 2026

    The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2025-0244

    Last Modified: 20 Apr 2026

    When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2022-22363

    Last Modified: 3 Jul 2025

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 7 Jan 2025
    3.7
    Low

    CVE-2021-20455

    Last Modified: 3 Jul 2025

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 7 Jan 2025
    8.2
    High

    CVE-2024-40702

    Last Modified: 3 Jul 2025

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2025-0298

    Last Modified: 7 Apr 2025

    A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the file /process_login.php. The manipulation of the argument usernm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2024-28778

    Last Modified: 3 Jul 2025

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2024-25037

    Last Modified: 3 Jul 2025

    IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.

    Published: 7 Jan 2025
    9.8
    Critical

    CVE-2025-21624

    Last Modified: 5 Sept 2025

    ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an image file, thus allowing a webshell or other malicious files to be stored and executed on the server. This attack vector exists in both the admin area and low-level user area. This vulnerability is fixed in 5.5.1 - 239.

    Published: 7 Jan 2025
    7.5
    High

    CVE-2025-21623

    Last Modified: 5 Sept 2025

    ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which results in a denial of service.

    Published: 7 Jan 2025
    7.5
    High

    CVE-2025-21622

    Last Modified: 5 Sept 2025

    ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar at any time. During deletion, ClipBucket checks for the avatar_url as a filepath within the avatars subdirectory. If the URL path exists within the avatars directory, ClipBucket will delete it. There is no check for path traversal sequences in the provided user input (stored in the DB as avatar_url) therefore the final $file variable could be tainted with path traversal sequences. This leads to file deletion outside of the intended scope of the avatars folder. This vulnerability is fixed in 5.5.1 - 237.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2024-52813

    Last Modified: 15 Apr 2026

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. matrix-sdk-crypto 0.8.0 adds a new VerificationLevel::VerificationViolation enum variant which indicates that a previously verified identity has been changed.

    Published: 7 Jan 2025
    5.3
    Medium

    CVE-2025-0297

    Last Modified: 30 Sept 2025

    A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 7 Jan 2025
    8.1
    High

    CVE-2024-53800

    Last Modified: 1 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in rezgo Rezgo rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a through <= 4.17.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2024-56056

    Last Modified: 1 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm simplecharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through <= 1.4.3.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2025-22294

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in theme funda Custom Field For WP Job Manager custom-field-for-wp-job-manager allows Reflected XSS.This issue affects Custom Field For WP Job Manager: from n/a through <= 1.3.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2025-22335

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rajib.dewan Opencart Product in WP opencart-product-in-wp allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through <= 1.0.1.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2025-22338

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lich_wang WP-tagMaker tagmaker allows Reflected XSS.This issue affects WP-tagMaker: from n/a through <= 0.2.2.

    Published: 7 Jan 2025
    7.6
    High

    CVE-2025-22502

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindValley Super PageMash mindvalley-pagemash allows SQL Injection.This issue affects MindValley Super PageMash: from n/a through <= 1.1.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2025-22503

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13.

    Published: 7 Jan 2025
    7.6
    High

    CVE-2025-22507

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in iDo8p WPMU Prefill Post wpmu-prefill-post allows SQL Injection.This issue affects WPMU Prefill Post: from n/a through <= 1.02.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22511

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ella Van Durpe Slides & Presentations slide allows Stored XSS.This issue affects Slides & Presentations: from n/a through <= 0.0.39.

    Published: 7 Jan 2025
    4.3
    Medium

    CVE-2025-22512

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in BoldGrid Help Scout help-scout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Help Scout: from n/a through <= 6.5.6.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22515

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simon Show Google Analytics widget show-google-analytics-widget allows Stored XSS.This issue affects Show Google Analytics widget: from n/a through <= 1.5.4.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22516

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hpinfosys Metadata SEO metadata-seo allows Stored XSS.This issue affects Metadata SEO: from n/a through <= 2.3.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22517

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Huson List Pages at Depth list-pages-at-depth allows Stored XSS.This issue affects List Pages at Depth: from n/a through <= 1.5.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22518

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsPoint Justified Image Gallery justified-image-gallery allows Stored XSS.This issue affects Justified Image Gallery: from n/a through <= 1.0.

    Published: 7 Jan 2025
    8.5
    High

    CVE-2025-22519

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables allows SQL Injection.This issue affects eDoc Easy Tables: from n/a through <= 1.29.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2025-22520

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tock Tock Widget tock-widget allows Cross Site Request Forgery.This issue affects Tock Widget: from n/a through <= 1.1.

    Published: 7 Jan 2025
    7.1
    High

    CVE-2025-22522

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roya khosravi SingSong singsong allows Stored XSS.This issue affects SingSong: from n/a through <= 1.2.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22524

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in formafzar فرم ساز فرم افزار formafzar allows Stored XSS.This issue affects فرم ساز فرم افزار: from n/a through <= 2.0.

    Published: 7 Jan 2025
    6.5
    Medium

    CVE-2025-22525

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bharat Kambariya Donation Block For PayPal donations-block allows Stored XSS.This issue affects Donation Block For PayPal: from n/a through <= 2.2.0.

    Published: 7 Jan 2025