CISA Bulletins - Vulnerability Summary for the Week of March 31, 2025

High Vulnerabilities

[CENTER][TABLE] [TR] [TH]Primary Vendor -- Product[/TH] [TH]Description[/TH] [TH]Published[/TH] [TH]CVSS Score[/TH] [TH]Source Info[/TH] [/TR] [TR] [TD]Aboobacker.--AB Google Map Travel [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Aboobacker. AB Google Map Travel allows Cross Site Request Forgery. This issue affects AB Google Map Travel : from n/a through 4.6.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31613&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31613]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31613')[/TD] [/TR] [TR] [TD]acme.sh project--acme.sh [/TD] [TD]The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.[/TD] [TD]2025-04-04[/TD] [TD][8.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32111&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N')[/TD] [TD][CVE-2025-32111]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32111')[/TD] [/TR] [TR] [TD]adamskaat--Countdown & Clock [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.[/TD] [TD]2025-04-01[/TD] [TD][9.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30841&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30841]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30841')[/TD] [/TR] [TR] [TD]adamskaat--Countdown, Coming Soon, Maintenance Countdown & Clock [/TD] [TD]The Countdown, Coming Soon, Maintenance - Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in some cases.[/TD] [TD]2025-04-04[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2270&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2270]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2270')[/TD] [/TR] [TR] [TD]AdminGeekZ--Varnish WordPress [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress allows Cross Site Request Forgery. This issue affects Varnish WordPress: from n/a through 1.7.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31616&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31616]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31616')[/TD] [/TR] [TR] [TD]Ads by WPQuads--Ads by WPQuads [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads by WPQuads allows SQL Injection. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30876&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30876]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30876')[/TD] [/TR] [TR] [TD]Ads by WPQuads--Ads by WPQuads [/TD] [TD]Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30855&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-30855]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30855')[/TD] [/TR] [TR] [TD]ageerle--ruoyi-ai [/TD] [TD]A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API Interface. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.2 is able to address this issue. The name of the patch is c0daf641fb25b244591b7a6c3affa35c69d321fe. It is recommended to upgrade the affected component.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3199&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3199]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3199')[/TD] [/TR] [TR] [TD]ageerle--ruoyi-ai [/TD] [TD]A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1 is able to address this issue. The name of the patch is 6382e177bf90cc56ff70521842409e35c50df32d. It is recommended to upgrade the affected component.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3202&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3202]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3202')[/TD] [/TR] [TR] [TD]aitool--Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One allows Blind SQL Injection. This issue affects Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One: from n/a through 2.1.7.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31564&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31564]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31564')[/TD] [/TR] [TR] [TD]aiven--aiven-extras [/TD] [TD]aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should install 1.1.16 and ensure they run the latest version issuing ALTER EXTENSION aiven_extras UPDATE TO '1.1.16' after installing it. This needs to happen in each database aiven_extras has been installed in.[/TD] [TD]2025-04-04[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31480&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31480]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31480')[/TD] [/TR] [TR] [TD]Alex Prokopenko / JustCoded--Just Post Preview Widget [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Prokopenko / JustCoded Just Post Preview Widget allows PHP Local File Inclusion. This issue affects Just Post Preview Widget: from n/a through 1.1.1.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32156&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32156]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32156')[/TD] [/TR] [TR] [TD]AMD--AMD Ryzen AI Software [/TD] [TD]Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or availability.[/TD] [TD]2025-04-02[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-36328&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H')[/TD] [TD][CVE-2024-36328]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36328')[/TD] [/TR] [TR] [TD]AMD--AMD Ryzen AI Software [/TD] [TD]Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a loss of confidentiality, integrity, or availability.[/TD] [TD]2025-04-02[/TD] [TD][7.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-36336&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H')[/TD] [TD][CVE-2024-36336]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36336')[/TD] [/TR] [TR] [TD]AMD--AMD Ryzen AI Software [/TD] [TD]Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of confidentiality, integrity or availability.[/TD] [TD]2025-04-02[/TD] [TD][7.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-36337&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H')[/TD] [TD][CVE-2024-36337]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36337')[/TD] [/TR] [TR] [TD]AMD--AMD Ryzen AI Software [/TD] [TD]Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.[/TD] [TD]2025-04-02[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0014&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-0014]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0014')[/TD] [/TR] [TR] [TD]Angelo Mandato--Blubrry PowerPress Podcasting plugin MultiSite add-on [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato Blubrry PowerPress Podcasting plugin MultiSite add-on allows Reflected XSS. This issue affects Blubrry PowerPress Podcasting plugin MultiSite add-on: from n/a through 0.1.1.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31436&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31436]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31436')[/TD] [/TR] [TR] [TD]Anzar Ahmed--Ni WooCommerce Product Enquiry [/TD] [TD]Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Product Enquiry allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ni WooCommerce Product Enquiry: from n/a through 4.1.8.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31580&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-31580]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31580')[/TD] [/TR] [TR] [TD]Aphotrax--Uptime Robot Plugin for WordPress [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows SQL Injection. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.[/TD] [TD]2025-03-31[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31547&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31547]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31547')[/TD] [/TR] [TR] [TD]api-platform--core [/TD] [TD]API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31481&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31481]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31481')[/TD] [/TR] [TR] [TD]api-platform--core [/TD] [TD]API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() method is meant to prevent the caching but the parent::normalize method that is called afterwards still creates the cache key and causes the issue. This vulnerability is fixed in 4.0.22.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31485&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31485]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31485')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24178&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24178]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24178')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A buffer overflow was addressed with improved bounds checking. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24237&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24237]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24237')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain elevated privileges.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24238&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24238]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24238')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30465&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30465]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30465')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]This issue was addressed with improved handling of symlinks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to delete files for which it does not have permission.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31182&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31182]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31182')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31183&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31183]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31183')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24173&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24173]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24173')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted file may lead to arbitrary code execution.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24243&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24243]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24243')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30456&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30456]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30456')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A validation issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote user may be able to cause a denial-of-service.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30471&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30471]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30471')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24148&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24148]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24148')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. "Block All Remote Content" may not apply for all mail previews.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24172&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24172]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24172')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24204&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24204]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24204')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24241&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24241]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24241')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24245&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24245]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24245')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24263&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24263]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24263')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24265&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24265]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24265')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24266&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24266]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24266')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24269&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24269]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24269')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to create symlinks to protected regions of the disk.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30457&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30457]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30457')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read files outside of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30458&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30458]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30458')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30461&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30461]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30461')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30462&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30462]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30462')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A Shortcut may run with admin privileges without authentication.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31194&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31194]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31194')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54533&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L')[/TD] [TD][CVE-2024-54533]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54533')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24170&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24170]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24170')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24267&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24267]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24267')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24277&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24277]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24277')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.[/TD] [TD]2025-03-31[/TD] [TD][7.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30437&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-30437]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30437')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][7.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30460&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-30460]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30460')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30464&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30464]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30464')[/TD] [/TR] [TR] [TD]apple -- safari [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24167&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24167]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24167')[/TD] [/TR] [TR] [TD]apple -- safari [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24264&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24264]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24264')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Password autofill may fill in passwords after failing authentication.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30430&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30430]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30430')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30433&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30433]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30433')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.[/TD] [TD]2025-03-31[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24180&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-24180]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24180')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4. An app may be able to bypass Privacy preferences.[/TD] [TD]2025-03-31[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24095&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L')[/TD] [TD][CVE-2025-24095]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24095')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed with improved data access restriction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Sensitive keychain data may be accessible from an iOS backup.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24221&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24221]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24221')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to cause unexpected system termination or write kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24257&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2025-24257]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24257')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24181&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24181]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24181')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24195&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24195]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24195')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24196&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24196]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24196')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to enable iCloud storage features without user consent.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24207&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24207]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24207')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24231&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24231]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24231')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24232&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24232]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24232')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24233&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24233]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24233')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]An injection issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24246&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24246]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24246')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker may be able to cause unexpected app termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24247&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24247]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24247')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to check the existence of an arbitrary path on the file system.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24249&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24249]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24249')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24250&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24250]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24250')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24253&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24253]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24253')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24256&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24256]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24256')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24259&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24259]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24259')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24260&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24260]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24260')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24273&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24273]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24273')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A logging issue was addressed with improved data redaction. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Deleting a conversation in Messages may expose user contact information in system logging.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30424&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30424]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30424')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30444&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30444]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30444')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An input validation issue was addressed.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30452&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30452]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30452')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.[/TD] [TD]2025-03-31[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24254&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24254]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24254')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][8.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24255&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24255]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24255')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to execute arbitrary code with kernel privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24228&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24228]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24228')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A sandboxed app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][7.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24229&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-24229]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24229')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24234&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24234]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24234')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain root privileges.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30449&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30449]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30449')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24190&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24190]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24190')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24211&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24211]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24211')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Playing a malicious audio file may lead to an unexpected app termination.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24230&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24230]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24230')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to enumerate a user's installed apps.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30426&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30426]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30426')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may lead to an unexpected process crash.[/TD] [TD]2025-03-31[/TD] [TD][7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24209&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H')[/TD] [TD][CVE-2025-24209]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24209')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with improved handling of floats. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A type confusion issue could lead to memory corruption.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24213&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24213]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24213')[/TD] [/TR] [TR] [TD]appsbd--Vitepos [/TD] [TD]Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.4.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22277&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22277]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22277')[/TD] [/TR] [TR] [TD]ApusThemes--WP RealEstate [/TD] [TD]The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2237&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2237]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2237')[/TD] [/TR] [TR] [TD]Ashish Ajani--Contact Form vCard Generator [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator allows Stored XSS. This issue affects Contact Form vCard Generator: from n/a through 2.4.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31582&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31582]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31582')[/TD] [/TR] [TR] [TD]Ashish Ajani--WP Copy Media URL [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Copy Media URL allows Stored XSS. This issue affects WP Copy Media URL: from n/a through 2.1.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31583&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31583]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31583')[/TD] [/TR] [TR] [TD]ATL Software SRL--AEC Kiosque [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ATL Software SRL AEC Kiosque allows Reflected XSS. This issue affects AEC Kiosque: from n/a through 1.9.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30902&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30902]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30902')[/TD] [/TR] [TR] [TD]Autodesk--Navisworks Freedom [/TD] [TD]A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.[/TD] [TD]2025-04-01[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1658&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-1658]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1658')[/TD] [/TR] [TR] [TD]Autodesk--Navisworks Freedom [/TD] [TD]A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.[/TD] [TD]2025-04-01[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1659&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-1659]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1659')[/TD] [/TR] [TR] [TD]Autodesk--Navisworks Freedom [/TD] [TD]A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.[/TD] [TD]2025-04-01[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1660&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-1660]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1660')[/TD] [/TR] [TR] [TD]Aviplugins--Videos [/TD] [TD]Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1.0.5.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31384&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31384]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31384')[/TD] [/TR] [TR] [TD]aweos--Email Notifications for Updates [/TD] [TD]The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.[/TD] [TD]2025-04-05[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2933&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2933]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2933')[/TD] [/TR] [TR] [TD]awesomesupport--Awesome Support WordPress HelpDesk & Support Plugin [/TD] [TD]The Awesome Support - WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/awesome-support directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 6.3.1.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13567&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2024-13567]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13567')[/TD] [/TR] [TR] [TD]AwesomeTOGI--Awesome Event Booking [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AwesomeTOGI Awesome Event Booking allows Reflected XSS.This issue affects Awesome Event Booking: from n/a through 2.8.4.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31416&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31416]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31416')[/TD] [/TR] [TR] [TD]Ays Pro--Quiz Maker [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.[/TD] [TD]2025-04-01[/TD] [TD][8.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30774&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30774]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30774')[/TD] [/TR] [TR] [TD]Ays Pro--Secure Copy Content Protection and Content Locking [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.4.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30905&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30905]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30905')[/TD] [/TR] [TR] [TD]Bastien Ho--Accounting for WooCommerce [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Accounting for WooCommerce allows PHP Local File Inclusion. This issue affects Accounting for WooCommerce: from n/a through 1.6.8.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30835&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30835]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30835')[/TD] [/TR] [TR] [TD]beego--beego [/TD] [TD]Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's RenderForm() function due to improper HTML escaping of user-controlled data. This vulnerability allows attackers to inject malicious JavaScript code that executes in victims' browsers, potentially leading to session hijacking, credential theft, or account takeover. The vulnerability affects any application using Beego's RenderForm() function with user-provided data. Since it is a high-level function generating an entire form markup, many developers would assume it automatically escapes attributes (the way most frameworks do). This vulnerability is fixed in 2.3.6.[/TD] [TD]2025-03-31[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30223&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N')[/TD] [TD][CVE-2025-30223]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30223')[/TD] [/TR] [TR] [TD]bentoml--BentoML [/TD] [TD]BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of BentoML. It allows any unauthenticated user to execute arbitrary code on the server. It exists an unsafe code segment in serde.py. This vulnerability is fixed in 1.4.3.[/TD] [TD]2025-04-04[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27520&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-27520]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27520')[/TD] [/TR] [TR] [TD]bigdrop.gr--Greek Multi Tool Fix peralinks, accents, auto create menus and more [/TD] [TD]Missing Authorization vulnerability in bigdrop.gr Greek Multi Tool - Fix peralinks, accents, auto create menus and more allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Greek Multi Tool - Fix peralinks, accents, auto create menus and more: from n/a through 2.3.1.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30797&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30797]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30797')[/TD] [/TR] [TR] [TD]Bit Apps--Bit Assist [/TD] [TD]Path Traversal vulnerability in Bit Apps Bit Assist allows Path Traversal. This issue affects Bit Assist: from n/a through 1.5.4.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30834&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-30834]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30834')[/TD] [/TR] [TR] [TD]Bob--Hostel [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30848&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30848]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30848')[/TD] [/TR] [TR] [TD]Bob--Watu Quiz [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz allows Reflected XSS. This issue affects Watu Quiz: from n/a through 3.4.2.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30844&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30844]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30844')[/TD] [/TR] [TR] [TD]Canon Inc.--Generic Plus PCL6 Printer Driver [/TD] [TD]Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver / Generic Plus LIPSLX Printer Driver / Generic Plus PS Printer Driver[/TD] [TD]2025-03-31[/TD] [TD][9.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1268&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L')[/TD] [TD][CVE-2025-1268]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1268')[/TD] [/TR] [TR] [TD]canonical--get-workflow-version-action [/TD] [TD]canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exception output, GitHub will automatically redact the secret from the GitHub Actions logs. However, the token may be truncated-causing part of the GITHUB_TOKEN to be displayed in plaintext in the GitHub Actions logs. Anyone with read access to the GitHub repository can view GitHub Actions logs. For public repositories, anyone can view the GitHub Actions logs. The opportunity to exploit this vulnerability is limited-the GITHUB_TOKEN is automatically revoked when the job completes. However, there is an opportunity for an attack in the time between the GITHUB_TOKEN being displayed in the logs and the completion of the job. Users using the github-token input are impacted. This vulnerability is fixed in 1.0.1.[/TD] [TD]2025-04-02[/TD] [TD][8.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31479&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H')[/TD] [TD][CVE-2025-31479]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31479')[/TD] [/TR] [TR] [TD]Catch Themes--Catch Dark Mode [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Catch Themes Catch Dark Mode allows PHP Local File Inclusion. This issue affects Catch Dark Mode: from n/a through 1.2.1.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32154&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32154]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32154')[/TD] [/TR] [TR] [TD]Cisco--Cisco Enterprise Chat and Email [/TD] [TD]A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.[/TD] [TD]2025-04-02[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-20139&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-20139]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-20139')[/TD] [/TR] [TR] [TD]Cisco--Cisco Meraki MX Firmware [/TD] [TD]A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user credentials on the affected device. This vulnerability exists because a variable is not initialized when an SSL VPN session is established. An attacker could exploit this vulnerability by supplying crafted attributes while establishing an SSL VPN session with an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to restart, resulting in the failure of the established SSL VPN sessions and forcing remote users to initiate a new VPN connection and reauthenticate. A sustained attack could prevent new SSL VPN connections from being established. Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers without manual intervention.[/TD] [TD]2025-04-02[/TD] [TD][7.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-20212&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H')[/TD] [TD][CVE-2025-20212]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-20212')[/TD] [/TR] [TR] [TD]click5--History Log by click5 [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log by click5 allows SQL Injection. This issue affects History Log by click5: from n/a through 1.0.13.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31531&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31531]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31531')[/TD] [/TR] [TR] [TD]cmsMinds--Pay with Contact Form 7 [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmsMinds Pay with Contact Form 7 allows SQL Injection. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32126&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32126]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32126')[/TD] [/TR] [TR] [TD]code-projects--Blood Bank Management System [/TD] [TD]A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /don.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3306&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3306]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3306')[/TD] [/TR] [TR] [TD]code-projects--Blood Bank Management System [/TD] [TD]A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3307&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3307]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3307')[/TD] [/TR] [TR] [TD]code-projects--Blood Bank Management System [/TD] [TD]A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /viewrequest.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3308&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3308]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3308')[/TD] [/TR] [TR] [TD]code-projects--Blood Bank Management System [/TD] [TD]A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/campsdetails.php. The manipulation of the argument hospital leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3309&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3309]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3309')[/TD] [/TR] [TR] [TD]code-projects--Blood Bank Management System [/TD] [TD]A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /admin/delete.php. The manipulation of the argument Search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3310&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3310]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3310')[/TD] [/TR] [TR] [TD]Coffee Code Tech--Plugin Oficial Getnet para WooCommerce [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coffee Code Tech Plugin Oficial - Getnet para WooCommerce allows Reflected XSS. This issue affects Plugin Oficial - Getnet para WooCommerce: from n/a through 1.7.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30906&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30906]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30906')[/TD] [/TR] [TR] [TD]contempoinc--Real Estate 7 WordPress [/TD] [TD]The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible if front-end listing submission has been enabled.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2891&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2891]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2891')[/TD] [/TR] [TR] [TD]coothemes--Easy WP Optimizer [/TD] [TD]Missing Authorization vulnerability in coothemes Easy WP Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy WP Optimizer: from n/a through 1.1.0.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32147&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32147]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32147')[/TD] [/TR] [TR] [TD]cozyvision1--SMS Alert Order Notifications WooCommerce [/TD] [TD]The SMS Alert Order Notifications - WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code "1234" and authenticate as any user, including administrators.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13553&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-13553]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13553')[/TD] [/TR] [TR] [TD]CreativeMindsSolutions--CM Download Manager [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager allows Path Traversal. This issue affects CM Download Manager: from n/a through 2.9.6.[/TD] [TD]2025-04-01[/TD] [TD][8.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30910&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30910]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30910')[/TD] [/TR] [TR] [TD]Cristiano Zanca--WooCommerce Fattureincloud [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristiano Zanca WooCommerce Fattureincloud allows Reflected XSS. This issue affects WooCommerce Fattureincloud: from n/a through 2.6.7.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30837&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30837]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30837')[/TD] [/TR] [TR] [TD]Crocoblock--JetWooBuilder [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder allows PHP Local File Inclusion.This issue affects JetWooBuilder: from n/a through 2.1.18.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31016&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31016]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31016')[/TD] [/TR] [TR] [TD]crosstec--Breezing Forms [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crosstec Breezing Forms allows Reflected XSS. This issue affects Breezing Forms: from n/a through 1.2.8.11.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30520&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30520]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30520')[/TD] [/TR] [TR] [TD]CrushFTP--CrushFTP [/TD] [TD]CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. The server first verifies the existence of the user by performing a call to login_user_pass() with no password requirement. This will authenticate the session through the HMAC verification process and up until the server checks for user verification once more. The vulnerability can be further stabilized, eliminating the need for successfully triggering a race condition, by sending a mangled AWS4-HMAC header. By providing only the username and a following slash (/), the server will successfully find a username, which triggers the successful anypass authentication process, but the server will fail to find the expected SignedHeaders entry, resulting in an index-out-of-bounds error that stops the code from reaching the session cleanup. Together, these issues make it trivial to authenticate as any known or guessable user (e.g., crushadmin), and can lead to a full compromise of the system by obtaining an administrative account.[/TD] [TD]2025-04-03[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31161&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31161]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31161')[/TD] [/TR] [TR] [TD]Cynob IT Consultancy--The Logo Slider [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cynob IT Consultancy The Logo Slider allows Reflected XSS. This issue affects The Logo Slider: from n/a through 1.0.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31571&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31571]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31571')[/TD] [/TR] [TR] [TD]Daisycon--Daisycon prijsvergelijkers [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.[/TD] [TD]2025-04-04[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32148&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32148]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32148')[/TD] [/TR] [TR] [TD]David Tufts--WP Cards [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Tufts WP Cards allows Reflected XSS. This issue affects WP Cards: from n/a through 1.5.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30547&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30547]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30547')[/TD] [/TR] [TR] [TD]davidfcarr--RSVPMarker [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.4.8.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31552&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31552]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31552')[/TD] [/TR] [TR] [TD]debounce--DeBounce Email Validator [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through 5.7.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31098&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31098]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31098')[/TD] [/TR] [TR] [TD]Dell--DD OS 8.3 [/TD] [TD]Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges.[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29987&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29987]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29987')[/TD] [/TR] [TR] [TD]Dell--Wyse Management Suite [/TD] [TD]Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.[/TD] [TD]2025-04-02[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29981&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-29981]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29981')[/TD] [/TR] [TR] [TD]Digihood--Digihood HTML Sitemap [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digihood Digihood HTML Sitemap allows Reflected XSS. This issue affects Digihood HTML Sitemap: from n/a through 3.1.1.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31901&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31901]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31901')[/TD] [/TR] [TR] [TD]Digital China--DCME-520 [/TD] [TD]A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-03-31[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3002&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3002]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3002')[/TD] [/TR] [TR] [TD]Dimitri Grassi--Salon booking system [/TD] [TD]Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system allows Privilege Escalation. This issue affects Salon booking system: from n/a through 10.11.[/TD] [TD]2025-04-01[/TD] [TD][7.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31560&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31560]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31560')[/TD] [/TR] [TR] [TD]Drupal--AI (Artificial Intelligence) [/TD] [TD]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31692&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31692]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31692')[/TD] [/TR] [TR] [TD]Drupal--Drupal core [/TD] [TD]Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31674&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31674]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31674')[/TD] [/TR] [TR] [TD]edmonparker--Read More & Accordion [/TD] [TD]The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.5. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.[/TD] [TD]2025-04-05[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0810&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-0810]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0810')[/TD] [/TR] [TR] [TD]Elaborate Bytes AG--Virtual CloneDrive [/TD] [TD]The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.[/TD] [TD]2025-04-04[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1865&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-1865]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1865')[/TD] [/TR] [TR] [TD]eleopard--Behance Portfolio Manager [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.[/TD] [TD]2025-03-31[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31526&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31526]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31526')[/TD] [/TR] [TR] [TD]eleopard--Behance Portfolio Manager [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32124&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32124]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32124')[/TD] [/TR] [TR] [TD]emotionalonlinestorytelling--Oracle Cards Lite [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite allows Reflected XSS. This issue affects Oracle Cards Lite: from n/a through 1.2.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30852&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30852]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30852')[/TD] [/TR] [TR] [TD]enituretechnology--Small Package Quotes Worldwide Express Edition [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes - Worldwide Express Edition allows Reflected XSS. This issue affects Small Package Quotes - Worldwide Express Edition: from n/a through 5.2.18.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31078&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31078]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31078')[/TD] [/TR] [TR] [TD]EPC--ez Form Calculator - WordPress plugin [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EPC ez Form Calculator - WordPress plugin allows Reflected XSS.This issue affects ez Form Calculator - WordPress plugin: from n/a through 2.14.1.2.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22282&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-22282]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22282')[/TD] [/TR] [TR] [TD]Erick Danzer--Easy Query WP Query Builder [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erick Danzer Easy Query - WP Query Builder allows Blind SQL Injection. This issue affects Easy Query - WP Query Builder: from n/a through 2.0.4.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32120&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32120]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32120')[/TD] [/TR] [TR] [TD]Essential Plugins by WP OnlineSupport--Slider a SlidersPack [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugins by WP OnlineSupport Slider a SlidersPack allows PHP Local File Inclusion. This issue affects Slider a SlidersPack: from n/a through 2.3.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32152&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32152]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32152')[/TD] [/TR] [TR] [TD]EXEIdeas International--WP AutoKeyword [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EXEIdeas International WP AutoKeyword allows SQL Injection. This issue affects WP AutoKeyword: from n/a through 1.0.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31579&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31579]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31579')[/TD] [/TR] [TR] [TD]Fahad Mahmood--Order Splitter for WooCommerce [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fahad Mahmood Order Splitter for WooCommerce allows SQL Injection. This issue affects Order Splitter for WooCommerce: from n/a through 5.3.0.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31089&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31089]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31089')[/TD] [/TR] [TR] [TD]Favethemes--Homey [/TD] [TD]Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.[/TD] [TD]2025-04-04[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-51800&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-51800]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-51800')[/TD] [/TR] [TR] [TD]Fortinet--FortiSIEM [/TD] [TD]A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements[/TD] [TD]2025-04-02[/TD] [TD][9.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2023-40714&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2023-40714]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40714')[/TD] [/TR] [TR] [TD]g5theme--Essential Real Estate [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate allows PHP Local File Inclusion. This issue affects Essential Real Estate: from n/a through 5.2.0.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30849&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30849]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30849')[/TD] [/TR] [TR] [TD]Gagan Deep Singh--PostmarkApp Email Integrator [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Gagan Deep Singh PostmarkApp Email Integrator allows Cross Site Request Forgery. This issue affects PostmarkApp Email Integrator: from n/a through 2.4.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31617&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31617]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31617')[/TD] [/TR] [TR] [TD]Gladinet--CentreStack [/TD] [TD]Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.[/TD] [TD]2025-04-03[/TD] [TD][9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30406&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30406]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30406')[/TD] [/TR] [TR] [TD]glenwpcoder--Drag and Drop Multiple File Upload for WooCommerce [/TD] [TD]The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php).[/TD] [TD]2025-04-05[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2941&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2941]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2941')[/TD] [/TR] [TR] [TD]Google--Chrome [/TD] [TD]Use after free in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3066&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3066]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3066')[/TD] [/TR] [TR] [TD]Google--Chrome [/TD] [TD]Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3067&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3067]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3067')[/TD] [/TR] [TR] [TD]Google--Chrome [/TD] [TD]Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3068&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3068]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3068')[/TD] [/TR] [TR] [TD]Google--Chrome [/TD] [TD]Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3069&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3069]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3069')[/TD] [/TR] [TR] [TD]Haozhe Xie--Google Font Fix [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haozhe Xie Google Font Fix allows Reflected XSS. This issue affects Google Font Fix: from n/a through 2.3.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30614&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30614]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30614')[/TD] [/TR] [TR] [TD]ho3einie--Material Dashboard [/TD] [TD]Authentication Bypass Using an Alternate Path or Channel vulnerability in ho3einie Material Dashboard allows Authentication Bypass. This issue affects Material Dashboard: from n/a through 1.4.5.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31095&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31095]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31095')[/TD] [/TR] [TR] [TD]ho3einie--Material Dashboard [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ho3einie Material Dashboard allows PHP Local File Inclusion. This issue affects Material Dashboard: from n/a through 1.4.5.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31097&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31097]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31097')[/TD] [/TR] [TR] [TD]Inaba Denki Sangyo Co., Ltd.--CHOCO TEI WATCHER mini (IB-MCT001) [/TD] [TD]Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-25211&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-25211]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-25211')[/TD] [/TR] [TR] [TD]Inaba Denki Sangyo Co., Ltd.--CHOCO TEI WATCHER mini (IB-MCT001) [/TD] [TD]Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-26689&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-26689]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-26689')[/TD] [/TR] [TR] [TD]Inaba Denki Sangyo Co., Ltd.--CHOCO TEI WATCHER mini (IB-MCT001) [/TD] [TD]Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attacker may obtain the product login password without authentication.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24517&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24517]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24517')[/TD] [/TR] [TR] [TD]InfornWeb--News & Blog Designer Pack [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack allows PHP Local File Inclusion. This issue affects News & Blog Designer Pack: from n/a through 4.0.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31082&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31082]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31082')[/TD] [/TR] [TR] [TD]Infoway LLC--Ebook Downloader [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader allows Cross Site Request Forgery. This issue affects Ebook Downloader: from n/a through 1.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31904&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31904]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31904')[/TD] [/TR] [TR] [TD]InstaWP--InstaWP Connect [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InstaWP InstaWP Connect allows PHP Local File Inclusion. This issue affects InstaWP Connect: from n/a through 0.1.0.82.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31387&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31387]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31387')[/TD] [/TR] [TR] [TD]itsourcecode--Online Blood Bank Management System [/TD] [TD]A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.0. This issue affects some unknown processing of the file /bbms.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3195&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3195]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3195')[/TD] [/TR] [TR] [TD]Ivanti--Connect Secure [/TD] [TD]A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.[/TD] [TD]2025-04-03[/TD] [TD][9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22457&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22457]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22457')[/TD] [/TR] [TR] [TD]Jakeii--Pesapal Gateway for Woocommerce [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakeii Pesapal Gateway for Woocommerce allows Reflected XSS. This issue affects Pesapal Gateway for Woocommerce: from n/a through 2.1.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30579&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30579]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30579')[/TD] [/TR] [TR] [TD]Jakub Glos--Sparkle Elementor Kit [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jakub Glos Sparkle Elementor Kit allows PHP Local File Inclusion. This issue affects Sparkle Elementor Kit: from n/a through 2.0.9.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32157&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32157]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32157')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins Templating Engine Plugin [/TD] [TD]In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31722&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31722]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31722')[/TD] [/TR] [TR] [TD]jhipster--generator-jhipster-entity-audit [/TD] [TD]generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath and also has access to these REST interface for calling the mentioned REST endpoints, using these lines of code can lead to unintended remote code execution. This vulnerability is fixed in 5.9.1.[/TD] [TD]2025-04-03[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31119&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31119]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31119')[/TD] [/TR] [TR] [TD]jiangmiao--WP Cleaner [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jiangmiao WP Cleaner allows Reflected XSS. This issue affects WP Cleaner: from n/a through 1.1.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31446&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31446]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31446')[/TD] [/TR] [TR] [TD]jooby-project--jooby [/TD] [TD]Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).[/TD] [TD]2025-03-31[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31129&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31129]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31129')[/TD] [/TR] [TR] [TD]JoomSky--JS Help Desk [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk allows SQL Injection. This issue affects JS Help Desk: from n/a through 2.9.2.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30886&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30886]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30886')[/TD] [/TR] [TR] [TD]JoomSky--JS Help Desk [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.2.[/TD] [TD]2025-04-01[/TD] [TD][8.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30878&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30878]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30878')[/TD] [/TR] [TR] [TD]JoomSky--JS Help Desk [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk allows PHP Local File Inclusion. This issue affects JS Help Desk: from n/a through 2.9.2.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30901&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30901]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30901')[/TD] [/TR] [TR] [TD]JoomSky--JS Help Desk [/TD] [TD]Missing Authorization vulnerability in JoomSky JS Help Desk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Help Desk: from n/a through 2.9.2.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30880&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30880]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30880')[/TD] [/TR] [TR] [TD]JoomSky--JS Help Desk [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30882&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30882]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30882')[/TD] [/TR] [TR] [TD]JoomSky--JS Job Manager [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32146&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32146]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32146')[/TD] [/TR] [TR] [TD]jupyterlab--jupyterlab-git [/TD] [TD]jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Git repository under a name that includes a shell command substitution string in the syntax $(). These directory names are allowed in macOS and a majority of Linux distributions. If a user starts jupyter-lab in a parent directory of this inappropriately-named Git repository, opens it, and clicks "Git > Open Git Repository in Terminal" from the menu bar, then the injected command is run in the user's shell without the user's permission. This issue is occurring because when that menu entry is clicked, jupyterlab-git opens the terminal and runs cd through the shell to set the current directory. Doing so runs any command substitution strings present in the directory name, which leads to the command injection issue described here. A previous patch provided an incomplete fix. This vulnerability is fixed in 0.51.1.[/TD] [TD]2025-04-03[/TD] [TD][7.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30370&vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H')[/TD] [TD][CVE-2025-30370]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30370')[/TD] [/TR] [TR] [TD]Kentico--Xperience [/TD] [TD]An unsafe reflection vulnerability in Kentico Xperience allows an unauthenticated attacker to kill the current process, leading to a Denial-of-Service condition. This issue affects Xperience: through 13.0.180.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2794&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-2794]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2794')[/TD] [/TR] [TR] [TD]Kentico--Xperience [/TD] [TD]Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.[/TD] [TD]2025-04-06[/TD] [TD][7.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32370&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32370]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32370')[/TD] [/TR] [TR] [TD]Labib Ahmed--Team Builder [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team Builder allows Reflected XSS. This issue affects Team Builder: from n/a through 1.3.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31907&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31907]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31907')[/TD] [/TR] [TR] [TD]leadfox--Leadfox for WordPress [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in leadfox Leadfox for WordPress allows Cross Site Request Forgery. This issue affects Leadfox for WordPress: from n/a through 2.1.8.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31585&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31585]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31585')[/TD] [/TR] [TR] [TD]lexicata--Lexicata [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lexicata Lexicata allows Reflected XSS. This issue affects Lexicata: from n/a through 1.0.16.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31900&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31900]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31900')[/TD] [/TR] [TR] [TD]Link Software LLC--HTML Forms [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS. This issue affects HTML Forms: from n/a through 1.5.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31080&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31080]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31080')[/TD] [/TR] [TR] [TD]Linux--Linux [/TD] [TD]In the Linux kernel, the following vulnerability has been resolved: keys: Fix UAF in key_put() Once a key's reference count has been reduced to 0, the garbage collector thread may destroy it at any time and so key_put() is not allowed to touch the key after that point. The most key_put() is normally allowed to do is to touch key_gc_work as that's a static global variable. However, in an effort to speed up the reclamation of quota, this is now done in key_put() once the key's usage is reduced to 0 - but now the code is looking at the key after the deadline, which is forbidden. Fix this by using a flag to indicate that a key can be gc'd now rather than looking at the key's refcount in the garbage collector.[/TD] [TD]2025-03-31[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-21893&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-21893]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-21893')[/TD] [/TR] [TR] [TD]Linux--Linux [/TD] [TD]In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode instantiation. The bug is that pde->proc_ops don't belong to /proc, it belongs to a module, therefore dereferencing it after /proc entry has been registered is a bug unless use_pde/unuse_pde() pair has been used. use_pde/unuse_pde can be avoided (2 atomic ops!) because pde->proc_ops never changes so information necessary for inode instantiation can be saved [I]before[/I] proc_register() in PDE itself and used later, avoiding pde->proc_ops->... dereference. rmmod lookup sys_delete_module proc_lookup_de pde_get(de); proc_get_inode(dir->i_sb, de); mod->exit() proc_remove remove_proc_subtree proc_entry_rundown(de); free_module(mod); if (S_ISREG(inode->i_mode)) if (de->proc_ops->proc_read_iter) --> As module is already freed, will trigger UAF BUG: unable to handle page fault for address: fffffbfff80a702b PGD 817fc4067 P4D 817fc4067 PUD 817fc0067 PMD 102ef4067 PTE 0 Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 26 UID: 0 PID: 2667 Comm: ls Tainted: G Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:proc_get_inode+0x302/0x6e0 RSP: 0018:ffff88811c837998 EFLAGS: 00010a06 RAX: dffffc0000000000 RBX: ffffffffc0538140 RCX: 0000000000000007 RDX: 1ffffffff80a702b RSI: 0000000000000001 RDI: ffffffffc0538158 RBP: ffff8881299a6000 R08: 0000000067bbe1e5 R09: 1ffff11023906f20 R10: ffffffffb560ca07 R11: ffffffffb2b43a58 R12: ffff888105bb78f0 R13: ffff888100518048 R14: ffff8881299a6004 R15: 0000000000000001 FS: 00007f95b9686840(0000) GS:ffff8883af100000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: fffffbfff80a702b CR3: 0000000117dd2000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: proc_lookup_de+0x11f/0x2e0 __lookup_slow+0x188/0x350 walk_component+0x2ab/0x4f0 path_lookupat+0x120/0x660 filename_lookup+0x1ce/0x560 vfs_statx+0xac/0x150 __do_sys_newstat+0x96/0x110 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e [[email][email protected][/email]: don't do 2 atomic ops on the common path][/TD] [TD]2025-04-03[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-21999&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-21999]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-21999')[/TD] [/TR] [TR] [TD]Linux--Linux [/TD] [TD]In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation frees skb so save the length before calling ->send() to avoid a use after free.[/TD] [TD]2025-04-03[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22004&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22004]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22004')[/TD] [/TR] [TR] [TD]logoninc--KB Support Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin [/TD] [TD]The KB Support - Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 1.7.3.2.[/TD] [TD]2025-04-05[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13604&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2024-13604]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13604')[/TD] [/TR] [TR] [TD]M. Ali Saleem--Support Helpdesk Ticket System Lite [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem Support Helpdesk Ticket System Lite allows Reflected XSS. This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31626&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31626]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31626')[/TD] [/TR] [TR] [TD]M. Tuhin--Ultimate Push Notifications [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M. Tuhin Ultimate Push Notifications allows SQL Injection. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31561&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31561]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31561')[/TD] [/TR] [TR] [TD]M. Tuhin--Ultimate Push Notifications [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Tuhin Ultimate Push Notifications allows Reflected XSS. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31548&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31548]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31548')[/TD] [/TR] [TR] [TD]madfishdigital--Bulk NoIndex & NoFollow Toolkit [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS. This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 2.16.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31537&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31537]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31537')[/TD] [/TR] [TR] [TD]magepeopleteam--WpTravelly [/TD] [TD]Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object Injection. This issue affects WpTravelly: from n/a through 1.8.7.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30892&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30892]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30892')[/TD] [/TR] [TR] [TD]manu225--Falling things [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in manu225 Falling things allows SQL Injection. This issue affects Falling things: from n/a through 1.08.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32203&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32203]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32203')[/TD] [/TR] [TR] [TD]marcoingraiti--Actionwear products sync [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync allows SQL Injection. This issue affects Actionwear products sync: from n/a through 2.3.3.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31619&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31619]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31619')[/TD] [/TR] [TR] [TD]markkinchin--Beds24 Online Booking [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in markkinchin Beds24 Online Booking allows PHP Local File Inclusion. This issue affects Beds24 Online Booking: from n/a through 2.0.26.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32155&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32155]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32155')[/TD] [/TR] [TR] [TD]Martin Nguyen--Next-Cart Store to WooCommerce Migration [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next-Cart Store to WooCommerce Migration allows SQL Injection. This issue affects Next-Cart Store to WooCommerce Migration: from n/a through 3.9.4.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30807&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30807]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30807')[/TD] [/TR] [TR] [TD]MDJM--MDJM Event Management [/TD] [TD]Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object Injection. This issue affects MDJM Event Management: from n/a through 1.7.5.2.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31074&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31074]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31074')[/TD] [/TR] [TR] [TD]Michel - xiligroup dev--xili-dictionary [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary allows Reflected XSS. This issue affects xili-dictionary: from n/a through 2.12.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30840&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30840]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30840')[/TD] [/TR] [TR] [TD]Michel - xiligroup dev--xili-language [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-language allows Reflected XSS. This issue affects xili-language: from n/a through 2.21.2.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31085&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31085]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31085')[/TD] [/TR] [TR] [TD]Microsoft--Azure Health Bot [/TD] [TD]An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.[/TD] [TD]2025-04-01[/TD] [TD][8.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-21384&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L')[/TD] [TD][CVE-2025-21384]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-21384')[/TD] [/TR] [TR] [TD]Microsoft--Azure Playwright [/TD] [TD]Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.[/TD] [TD]2025-03-31[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-26683&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-26683]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-26683')[/TD] [/TR] [TR] [TD]Microsoft--Microsoft Edge (Chromium-based) [/TD] [TD]Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-25000&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-25000]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-25000')[/TD] [/TR] [TR] [TD]Microsoft--Microsoft Edge (Chromium-based) [/TD] [TD]Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29815&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L')[/TD] [TD][CVE-2025-29815]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29815')[/TD] [/TR] [TR] [TD]MongoDB Inc--MongoDB Server [/TD] [TD]A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3085&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3085]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3085')[/TD] [/TR] [TR] [TD]MongoDB Inc--MongoDB Server [/TD] [TD]Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31, MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3083&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-3083]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3083')[/TD] [/TR] [TR] [TD]moshensky--CF7 Spreadsheets [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spreadsheets allows Reflected XSS. This issue affects CF7 Spreadsheets: from n/a through 2.3.2.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31536&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31536]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31536')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3030&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3030]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3030')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137 and Thunderbird < 137.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3034&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3034]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3034')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.[/TD] [TD]2025-04-01[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3029&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3029]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3029')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.[/TD] [TD]2025-04-01[/TD] [TD][7.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3032&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-3032]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3032')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]After selecting a malicious Windows [ICODE].url[/ICODE] shortcut from the local filesystem, an unexpected file could be uploaded. [I]This bug only affects Firefox on Windows. Other operating systems are unaffected.[/I] This vulnerability affects Firefox < 137 and Thunderbird < 137.[/TD] [TD]2025-04-01[/TD] [TD][7.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3033&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-3033]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3033')[/TD] [/TR] [TR] [TD]n/a--bigint-buffer [/TD] [TD]Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3194&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-3194]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3194')[/TD] [/TR] [TR] [TD]n/a--expand-object [/TD] [TD]Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like [B]proto[/B].[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3197&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3197]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3197')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.[/TD] [TD]2025-04-03[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-22611&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-22611]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22611')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.[/TD] [TD]2025-04-02[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-38392&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2024-38392]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-38392')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54802&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54802]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54802')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54803&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54803]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54803')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54804&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54804]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54804')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54805&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54805]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54805')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54806&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54806]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54806')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54807&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54807]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54807')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54808&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54808]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54808')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-54809&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-54809]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-54809')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22937&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22937]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22937')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22938&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22938]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22938')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22939&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22939]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22939')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.[/TD] [TD]2025-03-31[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22940&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-22940]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22940')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22941&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22941]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22941')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netwrix Password Secure 9.2.0.32454 allows OS command injection.[/TD] [TD]2025-04-03[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-26817&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-26817]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-26817')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Netwrix Password Secure through 9.2 allows command injection.[/TD] [TD]2025-04-03[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-26818&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-26818]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-26818')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.[/TD] [TD]2025-04-02[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29062&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29062]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29062')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.[/TD] [TD]2025-04-02[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29063&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29063]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29063')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.[/TD] [TD]2025-04-02[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29085&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29085]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29085')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.[/TD] [TD]2025-04-03[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29647&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29647]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29647')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-45198&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-45198]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-45198')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-45199&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-45199]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-45199')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22923&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22923]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22923')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22924&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22924]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22924')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.[/TD] [TD]2025-04-02[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-37917&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2024-37917]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-37917')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-47212&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2024-47212]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-47212')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-47213&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2024-47213]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-47213')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.[/TD] [TD]2025-04-02[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22925&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-22925]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22925')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.[/TD] [TD]2025-04-01[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29033&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-29033]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29033')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding identified a bug in a third-party calling program, not in lcms.[/TD] [TD]2025-04-01[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29069&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-29069]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29069')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29070&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-29070]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29070')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.[/TD] [TD]2025-04-03[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29504&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29504]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29504')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).[/TD] [TD]2025-04-02[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30080&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-30080]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30080')[/TD] [/TR] [TR] [TD]n/a--spatie/browsershot [/TD] [TD]Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.[/TD] [TD]2025-04-04[/TD] [TD][8.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3192&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N')[/TD] [TD][CVE-2025-3192]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3192')[/TD] [/TR] [TR] [TD]Name.ly--Quick Localization [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30607&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30607]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30607')[/TD] [/TR] [TR] [TD]Nick McReynolds--Product Table by WBW [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick McReynolds Product Table by WBW allows Reflected XSS. This issue affects Product Table by WBW: from n/a through 2.1.4.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31086&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31086]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31086')[/TD] [/TR] [TR] [TD]NiteoThemes--CMP Coming Soon & Maintenance [/TD] [TD]Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP - Coming Soon & Maintenance allows Using Malicious Files. This issue affects CMP - Coming Soon & Maintenance: from n/a through 4.1.13.[/TD] [TD]2025-04-04[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32118&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32118]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32118')[/TD] [/TR] [TR] [TD]noonnoo--Gravel [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noonnoo Gravel allows Reflected XSS.This issue affects Gravel: from n/a through 1.6.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31418&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31418]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31418')[/TD] [/TR] [TR] [TD]NotFound--Apptivo Business Site CRM [/TD] [TD]Missing Authorization vulnerability in NotFound Apptivo Business Site CRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apptivo Business Site CRM: from n/a through 5.3.[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31909&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-31909]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31909')[/TD] [/TR] [TR] [TD]NotFound--Delete Post Revision [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Delete Post Revision allows Reflected XSS. This issue affects Delete Post Revision: from n/a through 1.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31454&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31454]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31454')[/TD] [/TR] [TR] [TD]NotFound--DigiWidgets Image Editor [/TD] [TD]Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.[/TD] [TD]2025-04-01[/TD] [TD][10]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30580&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30580]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30580')[/TD] [/TR] [TR] [TD]NotFound--Flickr Photostream [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flickr Photostream allows Reflected XSS. This issue affects Flickr Photostream: from n/a through 3.1.8.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31467&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31467]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31467')[/TD] [/TR] [TR] [TD]NotFound--Flickr set slideshows [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Flickr set slideshows allows SQL Injection. This issue affects Flickr set slideshows: from n/a through 0.9.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30589&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30589]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30589')[/TD] [/TR] [TR] [TD]NotFound--Frizzly [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Frizzly allows Reflected XSS. This issue affects Frizzly: from n/a through 1.1.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30554&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30554]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30554')[/TD] [/TR] [TR] [TD]NotFound--Kento WordPress Stats [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Kento WordPress Stats allows Stored XSS. This issue affects Kento WordPress Stats: from n/a through 1.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30559&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30559]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30559')[/TD] [/TR] [TR] [TD]NotFound--Latest Custom Post Type Updates [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Latest Custom Post Type Updates allows Reflected XSS. This issue affects Latest Custom Post Type Updates: from n/a through 1.3.0.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30616&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30616]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30616')[/TD] [/TR] [TR] [TD]NotFound--Limit Max IPs Per User [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Limit Max IPs Per User allows DOM-Based XSS. This issue affects Limit Max IPs Per User: from n/a through 1.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31455&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31455]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31455')[/TD] [/TR] [TR] [TD]NotFound--MediaView [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MediaView allows Reflected XSS. This issue affects MediaView: from n/a through 1.1.2.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31898&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31898]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31898')[/TD] [/TR] [TR] [TD]NotFound--NanoSupport [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NanoSupport allows Reflected XSS. This issue affects NanoSupport: from n/a through 0.6.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31461&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31461]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31461')[/TD] [/TR] [TR] [TD]NotFound--OK Poster Group [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound OK Poster Group allows Reflected XSS. This issue affects OK Poster Group: from n/a through 1.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30544&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30544]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30544')[/TD] [/TR] [TR] [TD]NotFound--Pages Order [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pages Order allows Reflected XSS. This issue affects Pages Order: from n/a through 1.1.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31445&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31445]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31445')[/TD] [/TR] [TR] [TD]NotFound--Search engine keywords highlighter [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Search engine keywords highlighter allows Reflected XSS. This issue affects Search engine keywords highlighter: from n/a through 0.1.3.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31442&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31442]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31442')[/TD] [/TR] [TR] [TD]NotFound--Social Share And Social Locker [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Social Share And Social Locker allows Blind SQL Injection. This issue affects Social Share And Social Locker: from n/a through 1.4.2.[/TD] [TD]2025-04-03[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31911&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31911]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31911')[/TD] [/TR] [TR] [TD]NotFound--Social Share And Social Locker [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Social Share And Social Locker allows Reflected XSS. This issue affects Social Share And Social Locker: from n/a through 1.4.1.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31902&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31902]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31902')[/TD] [/TR] [TR] [TD]NotFound--Team Rosters [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Team Rosters allows Reflected XSS. This issue affects Team Rosters: from n/a through 4.7.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31905&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31905]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31905')[/TD] [/TR] [TR] [TD]NotFound--Tidekey [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tidekey allows Reflected XSS. This issue affects Tidekey: from n/a through 1.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30563&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30563]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30563')[/TD] [/TR] [TR] [TD]NotFound--WP Bookmarks [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Bookmarks allows Reflected XSS. This issue affects WP Bookmarks: from n/a through 1.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31431&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31431]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31431')[/TD] [/TR] [TR] [TD]NotFound--WP_Identicon [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP_Identicon allows Reflected XSS. This issue affects WP_Identicon: from n/a through 2.0.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31468&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31468]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31468')[/TD] [/TR] [TR] [TD]NotFound--Wptobe-signinup [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Wptobe-signinup allows Reflected XSS. This issue affects Wptobe-signinup: from n/a through 1.1.2.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30611&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30611]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30611')[/TD] [/TR] [TR] [TD]NotFound--XV Random Quotes [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound XV Random Quotes allows Reflected XSS. This issue affects XV Random Quotes: from n/a through 1.37.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31903&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31903]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31903')[/TD] [/TR] [TR] [TD]onOffice GmbH--onOffice for WP-Websites [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in onOffice GmbH onOffice for WP-Websites allows SQL Injection. This issue affects onOffice for WP-Websites: from n/a through 5.7.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32127&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32127]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32127')[/TD] [/TR] [TR] [TD]Open Source Robotics Foundation--Robot Operating System (ROS) [/TD] [TD]A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code. This issue has now been fixed for ROS Noetic via commit 3d93ac13603438323d7e9fa74e879e45c5fe2e8e.[/TD] [TD]2025-04-02[/TD] [TD][8.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-39780&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-39780]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-39780')[/TD] [/TR] [TR] [TD]OpenVPN--OpenVPN [/TD] [TD]OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-4877&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-4877]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4877')[/TD] [/TR] [TR] [TD]OTWthemes--Sidebar Manager Light [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.1.8.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32112&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32112]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32112')[/TD] [/TR] [TR] [TD]owenr88--Simple Contact Forms [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in owenr88 Simple Contact Forms allows Stored XSS. This issue affects Simple Contact Forms: from n/a through 1.6.4.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31615&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31615]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31615')[/TD] [/TR] [TR] [TD]Parakoos--Image Wall [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall allows Reflected XSS. This issue affects Image Wall: from n/a through 3.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30869&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30869]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30869')[/TD] [/TR] [TR] [TD]Pepro Dev. Group--PeproDev CF7 Database [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev CF7 Database allows Stored XSS. This issue affects PeproDev CF7 Database: from n/a through 2.0.0.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31573&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31573]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31573')[/TD] [/TR] [TR] [TD]pgadmin.org--pgAdmin 4 [/TD] [TD]Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the Python eval() function, allowing arbitrary code execution. This issue affects pgAdmin 4: before 9.2.[/TD] [TD]2025-04-03[/TD] [TD][9.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2945&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2945]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2945')[/TD] [/TR] [TR] [TD]pgadmin.org--pgAdmin 4 [/TD] [TD]pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.[/TD] [TD]2025-04-03[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2946&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H')[/TD] [TD][CVE-2025-2946]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2946')[/TD] [/TR] [TR] [TD]PHPGurukul--Boat Booking System [/TD] [TD]A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3147&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3147]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3147')[/TD] [/TR] [TR] [TD]PHPGurukul--Bus Pass Management System [/TD] [TD]A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3146&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3146]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3146')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /edit-category.php?id=8. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3006&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3006]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3006')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument logindetail leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3187&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3187]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3187')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability classified as critical has been found in PHPGurukul e-Diary Management System 1.0. This affects an unknown part of the file /add-notes.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3188&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3188]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3188')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects unknown code of the file /view-note.php?noteid=11. The manipulation of the argument remark leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3213&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3213]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3213')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been classified as critical. This affects an unknown part of the file /password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3216&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3216]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3216')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3217&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3217]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3217')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3220&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3220]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3220')[/TD] [/TR] [TR] [TD]PHPGurukul--e-Diary Management System [/TD] [TD]A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3265&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3265]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3265')[/TD] [/TR] [TR] [TD]PHPGurukul--Men Salon Management System [/TD] [TD]A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /appointment.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-05[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3299&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3299]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3299')[/TD] [/TR] [TR] [TD]PHPGurukul--Men Salon Management System [/TD] [TD]A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3311&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3311]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3311')[/TD] [/TR] [TR] [TD]PHPGurukul--Men Salon Management System [/TD] [TD]A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids[] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3312&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3312]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3312')[/TD] [/TR] [TR] [TD]PHPGurukul--Men Salon Management System [/TD] [TD]A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is an unknown function of the file /admin/add-customer.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3313&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3313]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3313')[/TD] [/TR] [TR] [TD]PHPGurukul--Men Salon Management System [/TD] [TD]A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3316&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3316]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3316')[/TD] [/TR] [TR] [TD]PHPGurukul--Old Age Home Management System [/TD] [TD]A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3258&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3258]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3258')[/TD] [/TR] [TR] [TD]PHPGurukul--Online Fire Reporting System [/TD] [TD]A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3238&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3238]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3238')[/TD] [/TR] [TR] [TD]PHPGurukul--Online Fire Reporting System [/TD] [TD]A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3239&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3239]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3239')[/TD] [/TR] [TR] [TD]PHPGurukul--Online Fire Reporting System [/TD] [TD]A vulnerability, which was classified as critical, has been found in PHPGurukul Online Fire Reporting System 1.2. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3240&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3240]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3240')[/TD] [/TR] [TR] [TD]PHPGurukul--Online Security Guards Hiring System [/TD] [TD]A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3137&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3137]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3137')[/TD] [/TR] [TR] [TD]PHPGurukul--Online Security Guards Hiring System [/TD] [TD]A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3138&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3138]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3138')[/TD] [/TR] [TR] [TD]PHPGurukul--Time Table Generator System [/TD] [TD]A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3168&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3168]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3168')[/TD] [/TR] [TR] [TD]PHPGurukul--Zoo Management System [/TD] [TD]A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3231&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3231]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3231')[/TD] [/TR] [TR] [TD]PickPlugins--Testimonial Slider [/TD] [TD]Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider allows Object Injection. This issue affects Testimonial Slider: from n/a through 2.0.13.[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30889&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30889]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30889')[/TD] [/TR] [TR] [TD]PiExtract--SOOP-CLM [/TD] [TD]SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.[/TD] [TD]2025-03-31[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3011&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3011]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3011')[/TD] [/TR] [TR] [TD]pluggabl--Booster for WooCommerce [/TD] [TD]The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.[/TD] [TD]2025-04-04[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13744&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-13744]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13744')[/TD] [/TR] [TR] [TD]pluggabl--Booster for WooCommerce [/TD] [TD]The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-01[/TD] [TD][7.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-12278&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2024-12278]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-12278')[/TD] [/TR] [TR] [TD]pluggabl--Booster for WooCommerce [/TD] [TD]The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.[/TD] [TD]2025-04-04[/TD] [TD][7.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13708&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2024-13708]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13708')[/TD] [/TR] [TR] [TD]podpirate--Access Areas [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podpirate Access Areas allows Reflected XSS. This issue affects Access Areas: from n/a through 1.5.19.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30913&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30913]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30913')[/TD] [/TR] [TR] [TD]primersoftware--Primer MyData for Woocommerce [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Primer MyData for Woocommerce allows Reflected XSS. This issue affects Primer MyData for Woocommerce: from n/a through n/a.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30924&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30924]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30924')[/TD] [/TR] [TR] [TD]ProfitShare.ro--WP Profitshare [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare allows Stored XSS. This issue affects WP Profitshare: from n/a through 1.4.9.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31906&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31906]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31906')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affects an unknown part of the file /admin_user.php. The manipulation of the argument block_id/unblock_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3170&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3170]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3170')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3171&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3171]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3171')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyer_booking.php. The manipulation of the argument unblock_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3172&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3172]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3172')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3173&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3173]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3173')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3174&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3174]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3174')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3175&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3175]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3175')[/TD] [/TR] [TR] [TD]Project Worlds--Online Lawyer Management System [/TD] [TD]A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3176&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3176]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3176')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3178&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3178]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3178')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3179&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3179]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3179')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3180&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3180]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3180')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this issue is some unknown functionality of the file /patient/appointment.php?scheduleDate=1&appid=1. The manipulation of the argument scheduleDate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3181&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3181]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3181')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file /patient/getschedule.php. The manipulation of the argument q leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3182&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3182]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3182')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3183&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3183]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3183')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /patient/profile.php?patientId=1. The manipulation of the argument patientFirstName leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3184&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3184]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3184')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3185&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3185]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3185')[/TD] [/TR] [TR] [TD]projectworlds--Online Doctor Appointment Booking System [/TD] [TD]A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the argument appid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3186&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3186]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3186')[/TD] [/TR] [TR] [TD]Property Hive--Houzez Property Feed [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed allows Path Traversal. This issue affects Houzez Property Feed: from n/a through 2.5.4.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30793&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30793]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30793')[/TD] [/TR] [TR] [TD]qinguoyi--TinyWebServer [/TD] [TD]A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3266&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3266]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3266')[/TD] [/TR] [TR] [TD]RadiusTheme--Radius Blocks [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Radius Blocks allows PHP Local File Inclusion. This issue affects Radius Blocks: from n/a through 2.2.1.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32159&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32159]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32159')[/TD] [/TR] [TR] [TD]ramanparashar--Useinfluence [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ramanparashar Useinfluence allows Stored XSS. This issue affects Useinfluence: from n/a through 1.0.8.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31625&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31625]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31625')[/TD] [/TR] [TR] [TD]Rameez Iqbal--Real Estate Manager [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32150&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32150]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32150')[/TD] [/TR] [TR] [TD]randyjensen--RJ Quickcharts [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts allows SQL Injection. This issue affects RJ Quickcharts: from n/a through 0.6.1.[/TD] [TD]2025-04-01[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31024&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31024]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31024')[/TD] [/TR] [TR] [TD]Red Hat--OpenShift Lightspeed [/TD] [TD]A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2586&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-2586]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2586')[/TD] [/TR] [TR] [TD]Red Hat--Red Hat Enterprise Linux 6 [/TD] [TD]A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.[/TD] [TD]2025-04-03[/TD] [TD][7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2784&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H')[/TD] [TD][CVE-2025-2784]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2784')[/TD] [/TR] [TR] [TD]Red Hat--Red Hat Enterprise Linux 6 [/TD] [TD]A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS).[/TD] [TD]2025-04-03[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32049&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-32049]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32049')[/TD] [/TR] [TR] [TD]Renzo Tejada--Libro de Reclamaciones y Quejas [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Renzo Tejada Libro de Reclamaciones y Quejas allows Cross Site Request Forgery. This issue affects Libro de Reclamaciones y Quejas: from n/a through 0.9.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32113&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32113]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32113')[/TD] [/TR] [TR] [TD]reputeinfosystems--BookingPress [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress allows SQL Injection. This issue affects BookingPress: from n/a through 1.1.28.[/TD] [TD]2025-04-01[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31910&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31910]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31910')[/TD] [/TR] [TR] [TD]richtexteditor--Rich Text Editor [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in richtexteditor Rich Text Editor allows Stored XSS. This issue affects Rich Text Editor: from n/a through 1.0.1.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31623&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31623]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31623')[/TD] [/TR] [TR] [TD]rickonline_nl--Better WishList API [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rickonline_nl Better WishList API allows Reflected XSS. This issue affects Better WishList API: from n/a through 1.1.4.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30798&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30798]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30798')[/TD] [/TR] [TR] [TD]riosisgroup--Rio Video Gallery [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31566&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31566]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31566')[/TD] [/TR] [TR] [TD]rocketelements--Split Test For Elementor [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rocketelements Split Test For Elementor allows SQL Injection. This issue affects Split Test For Elementor: from n/a through 1.8.2.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32204&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32204]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32204')[/TD] [/TR] [TR] [TD]Rometheme--RomethemeKit For Elementor [/TD] [TD]Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RomethemeKit For Elementor allows Command Injection. This issue affects RomethemeKit For Elementor: from n/a through 1.5.4.[/TD] [TD]2025-04-01[/TD] [TD][9.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30911&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30911]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30911')[/TD] [/TR] [TR] [TD]rustaurius--Front End Users [/TD] [TD]The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.[/TD] [TD]2025-04-02[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2005&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2005]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2005')[/TD] [/TR] [TR] [TD]rzfarrell--CGM Event Calendar [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rzfarrell CGM Event Calendar allows Reflected XSS. This issue affects CGM Event Calendar: from n/a through 0.8.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31462&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31462]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31462')[/TD] [/TR] [TR] [TD]S--WordPress Galleria [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in S WordPress Galleria allows Reflected XSS. This issue affects WordPress Galleria: from n/a through 1.4.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31441&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31441]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31441')[/TD] [/TR] [TR] [TD]Sabuj Kundu--CBX Poll [/TD] [TD]Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll allows Object Injection. This issue affects CBX Poll: from n/a through 1.2.7.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31612&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31612]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31612')[/TD] [/TR] [TR] [TD]Salesmate.io--Salesmate Add-On for Gravity Forms [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Salesmate Add-On for Gravity Forms allows SQL Injection. This issue affects Salesmate Add-On for Gravity Forms: from n/a through 2.0.3.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31551&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31551]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31551')[/TD] [/TR] [TR] [TD]Saleswonder Team Tobias--WP2LEADS [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.4.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30827&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30827]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30827')[/TD] [/TR] [TR] [TD]Sami Ahmed Siddiqui--JSON Structuring Markup [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup allows Stored XSS. This issue affects JSON Structuring Markup: from n/a through 0.1.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31908&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31908]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31908')[/TD] [/TR] [TR] [TD]sequel.io--Sequel [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sequel.Io Sequel allows Reflected XSS.This issue affects Sequel: from n/a through 1.0.11.[/TD] [TD]2025-04-04[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31389&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31389]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31389')[/TD] [/TR] [TR] [TD]Shamalli--Web Directory Free [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free allows Stored XSS. This issue affects Web Directory Free: from n/a through 1.7.6.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30908&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30908]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30908')[/TD] [/TR] [TR] [TD]shiptrack--Booking Calendar and Notification [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shiptrack Booking Calendar and Notification allows Blind SQL Injection.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.[/TD] [TD]2025-04-04[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31403&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31403]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31403')[/TD] [/TR] [TR] [TD]shopperapprovedapp--Shopper Approved Reviews [/TD] [TD]The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_callback_update_sa_option() function in versions 2.0 to 2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.[/TD] [TD]2025-04-02[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3063&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3063]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3063')[/TD] [/TR] [TR] [TD]shopperdotcom--Shopper [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shopper allows SQL Injection. This issue affects Shopper: from n/a through 3.2.5.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31534&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31534]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31534')[/TD] [/TR] [TR] [TD]ShortPixel--Enable Media Replace [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31081&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31081]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31081')[/TD] [/TR] [TR] [TD]silvasoft--Silvasoft boekhouden [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silvasoft Silvasoft boekhouden allows SQL Injection. This issue affects Silvasoft boekhouden: from n/a through 3.0.1.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32125&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32125]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32125')[/TD] [/TR] [TR] [TD]silverplugins217--Multiple Shipping And Billing Address For Woocommerce [/TD] [TD]Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows Object Injection. This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.5.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31087&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31087]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31087')[/TD] [/TR] [TR] [TD]smackcoders--Import Export Suite for CSV and XML Datafeed [/TD] [TD]The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2007&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2025-2007]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2007')[/TD] [/TR] [TR] [TD]smackcoders--Import Export Suite for CSV and XML Datafeed [/TD] [TD]The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2008&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2008]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2008')[/TD] [/TR] [TR] [TD]SourceCodester--Apartment Visitor Management System [/TD] [TD]A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument secode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3314&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3314]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3314')[/TD] [/TR] [TR] [TD]SourceCodester--Apartment Visitor Management System [/TD] [TD]A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3315&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3315]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3315')[/TD] [/TR] [TR] [TD]SourceCodester--Gym Management System [/TD] [TD]A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][7.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3151&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3151]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3151')[/TD] [/TR] [TR] [TD]SquirrelMail--SquirrelMail [/TD] [TD]mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.[/TD] [TD]2025-04-02[/TD] [TD][7.2]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30090&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-30090]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30090')[/TD] [/TR] [TR] [TD]STMicroelectronics--X-CUBE-AZRT-H7RS [/TD] [TD]A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.[/TD] [TD]2025-04-02[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-45064&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2024-45064]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-45064')[/TD] [/TR] [TR] [TD]Stylemix--MasterStudy LMS [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS allows PHP Local File Inclusion. This issue affects MasterStudy LMS: from n/a through 3.5.23.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32141&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32141]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32141')[/TD] [/TR] [TR] [TD]Stylemix--Motors [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.65.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32142&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32142]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32142')[/TD] [/TR] [TR] [TD]Stylemix--uListing [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.9.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32122&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32122]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32122')[/TD] [/TR] [TR] [TD]SuitePlugins--Video & Photo Gallery for Ultimate Member [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows SQL Injection. This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.3.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32121&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32121]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32121')[/TD] [/TR] [TR] [TD]sunshinephotocart -- sunshine_photo_cart [/TD] [TD]Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows Object Injection. This issue affects Sunshine Photo Cart: from n/a through 3.4.10.[/TD] [TD]2025-04-01[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31084&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31084]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31084')[/TD] [/TR] [TR] [TD]Sven Lehnert--BuddyForms [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sven Lehnert BuddyForms allows PHP Local File Inclusion. This issue affects BuddyForms: from n/a through 2.8.15.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32151&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32151]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32151')[/TD] [/TR] [TR] [TD]ta2g--Tantyyellow [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ta2g Tantyyellow allows Reflected XSS.This issue affects Tantyyellow: from n/a through 1.0.0.5.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-23995&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-23995]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-23995')[/TD] [/TR] [TR] [TD]tagDiv--tagDiv Composer [/TD] [TD]The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauthenticated attackers to Instantiate a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.[/TD] [TD]2025-04-04[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13645&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-13645]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13645')[/TD] [/TR] [TR] [TD]TangibleWP--Vehica Core [/TD] [TD]The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change escalate their privileges to Administrator.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3105&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3105]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3105')[/TD] [/TR] [TR] [TD]Tenda--AC10 [/TD] [TD]A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3161&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3161]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3161')[/TD] [/TR] [TR] [TD]Tenda--RX3 [/TD] [TD]A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3259&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3259]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3259')[/TD] [/TR] [TR] [TD]The Events Calendar--Event Tickets [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Events Calendar Event Tickets allows Reflected XSS. This issue affects Event Tickets: from n/a through 5.20.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30794&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30794]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30794')[/TD] [/TR] [TR] [TD]The-Commit-Company--raven [/TD] [TD]Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.10.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31132&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2025-31132]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31132')[/TD] [/TR] [TR] [TD]TLA Media--GTM Kit [/TD] [TD]Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit allows Retrieve Embedded Sensitive Data. This issue affects GTM Kit: from n/a through 2.3.1.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31001&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31001]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31001')[/TD] [/TR] [TR] [TD]Tomdever--wpForo Forum [/TD] [TD]Incorrect Privilege Assignment vulnerability in Tomdever wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.4.2.[/TD] [TD]2025-04-04[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31420&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L')[/TD] [TD][CVE-2025-31420]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31420')[/TD] [/TR] [TR] [TD]torsteino--PostMash [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash allows SQL Injection. This issue affects PostMash: from n/a through 1.0.3.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30622&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30622]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30622')[/TD] [/TR] [TR] [TD]Tribulant Software--Snow Storm [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30858&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30858]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30858')[/TD] [/TR] [TR] [TD]Ubuntu--Ubuntu package linux-bluefield [/TD] [TD]Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.[/TD] [TD]2025-03-31[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2023-0881&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2023-0881]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-0881')[/TD] [/TR] [TR] [TD]uncannyowl--Uncanny Automator Easy Automation, Integration, Webhooks & Workflow Builder Plugin [/TD] [TD]The Uncanny Automator - Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call() function. This makes it possible for unauthenticated attackers to set the role of arbitrary users to administrator granting full access to the site, though privilege escalation requires an active account on the site so this is considered an authenticated privilege escalation.[/TD] [TD]2025-04-04[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2075&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2075]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2075')[/TD] [/TR] [TR] [TD]Unraid--Unraid [/TD] [TD]Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.[/TD] [TD]2025-03-31[/TD] [TD][9.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29266&vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-29266]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29266')[/TD] [/TR] [TR] [TD]VarDump s.r.l.--Advanced Post Search [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VarDump s.r.l. Advanced Post Search allows Reflected XSS. This issue affects Advanced Post Search: from n/a through 1.1.0.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30548&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30548]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30548')[/TD] [/TR] [TR] [TD]Vikas Ratudi--VForm [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30778&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30778]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30778')[/TD] [/TR] [TR] [TD]Vimal Kava--AI Search Bar [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vimal Kava AI Search Bar allows Stored XSS. This issue affects AI Search Bar: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31563&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31563]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31563')[/TD] [/TR] [TR] [TD]vinagecko--VG WooCarousel [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vinagecko VG WooCarousel allows PHP Local File Inclusion. This issue affects VG WooCarousel: from n/a through 1.3.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32153&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-32153]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32153')[/TD] [/TR] [TR] [TD]VMware--VMware Aria operations [/TD] [TD]VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.[/TD] [TD]2025-04-01[/TD] [TD][7.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22231&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-22231]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22231')[/TD] [/TR] [TR] [TD]weblizar--About Author [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weblizar About Author allows Reflected XSS. This issue affects About Author: from n/a through 1.6.2.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30808&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30808]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30808')[/TD] [/TR] [TR] [TD]winkm89--teachPress [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in winkm89 teachPress allows SQL Injection. This issue affects teachPress: from n/a through 9.0.11.[/TD] [TD]2025-04-04[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32149&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-32149]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32149')[/TD] [/TR] [TR] [TD]wiredmindshelp--LeadLab by wiredminds [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wiredmindshelp LeadLab by wiredminds allows Reflected XSS. This issue affects LeadLab by wiredminds: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31568&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31568]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31568')[/TD] [/TR] [TR] [TD]Wisdomlogix Solutions Pvt. Ltd.--Fonts Manager | Custom Fonts [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wisdomlogix Solutions Pvt. Ltd. Fonts Manager | Custom Fonts allows Reflected XSS. This issue affects Fonts Manager | Custom Fonts: from n/a through 1.2.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31578&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31578]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31578')[/TD] [/TR] [TR] [TD]WofficeIO--Woffice Core [/TD] [TD]The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeaturedImage' function in all versions up to, and including, 5.4.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.[/TD] [TD]2025-04-04[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2780&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2780]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2780')[/TD] [/TR] [TR] [TD]woobewoo--Product Filter by WBW [/TD] [TD]The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend parameter in all versions up to, and including, 2.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2317&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-2317]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2317')[/TD] [/TR] [TR] [TD]WP Extended--The Ultimate WordPress Toolkit WP Extended [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit - WP Extended allows Reflected XSS. This issue affects The Ultimate WordPress Toolkit - WP Extended: from n/a through 3.0.14.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30796&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30796]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30796')[/TD] [/TR] [TR] [TD]WP Shuffle--Subscribe to Download Lite [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite: from n/a through 1.2.9.[/TD] [TD]2025-04-01[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30782&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30782]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30782')[/TD] [/TR] [TR] [TD]WP Travel Engine--WP Travel Engine [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.3.5.[/TD] [TD]2025-04-01[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30870&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30870]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30870')[/TD] [/TR] [TR] [TD]WP Wham--SKU Generator for WooCommerce [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham SKU Generator for WooCommerce allows Reflected XSS. This issue affects SKU Generator for WooCommerce: from n/a through 1.6.2.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30917&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30917]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30917')[/TD] [/TR] [TR] [TD]wp-buy--Related Posts Widget with Thumbnails [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in wp-buy Related Posts Widget with Thumbnails allows Stored XSS. This issue affects Related Posts Widget with Thumbnails: from n/a through 1.2.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31570&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31570]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31570')[/TD] [/TR] [TR] [TD]wp-buy--wordpress related Posts with thumbnails [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in wp-buy wordpress related Posts with thumbnails allows Stored XSS. This issue affects wordpress related Posts with thumbnails: from n/a through 3.0.0.1.[/TD] [TD]2025-03-31[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31569&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31569]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31569')[/TD] [/TR] [TR] [TD]WPClever--WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce [/TD] [TD]Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through 1.3.5.[/TD] [TD]2025-04-01[/TD] [TD][8.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30825&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30825]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30825')[/TD] [/TR] [TR] [TD]WPFactory--Advanced WooCommerce Product Sales Reporting [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting allows SQL Injection. This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through 3.1.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31553&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31553]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31553')[/TD] [/TR] [TR] [TD]WPglob--Auto scroll for reading [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPglob Auto scroll for reading allows Reflected XSS. This issue affects Auto scroll for reading: from n/a through 1.1.4.[/TD] [TD]2025-04-01[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31594&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31594]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31594')[/TD] [/TR] [TR] [TD]wphocus--My auctions allegro [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro allows Blind SQL Injection. This issue affects My auctions allegro: from n/a through 3.6.20.[/TD] [TD]2025-03-31[/TD] [TD][8.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31542&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-31542]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31542')[/TD] [/TR] [TR] [TD]wpshopee--Awesome Logos [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos allows Reflected XSS. This issue affects Awesome Logos: from n/a through 1.2.[/TD] [TD]2025-04-03[/TD] [TD][7.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31899&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31899]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31899')[/TD] [/TR] [TR] [TD]Xavi Ivars--XV Random Quotes [/TD] [TD]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes allows SQL Injection. This issue affects XV Random Quotes: from n/a through 1.40.[/TD] [TD]2025-04-01[/TD] [TD][9.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30971&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L')[/TD] [TD][CVE-2025-30971]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30971')[/TD] [/TR] [TR] [TD]Xorcom--CompletePBX [/TD] [TD]Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This issue affects CompletePBX: all versions up to and prior to 5.2.35[/TD] [TD]2025-03-31[/TD] [TD][9.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30004&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2025-30004]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30004')[/TD] [/TR] [TR] [TD]XTENDIFY--Woffice CRM [/TD] [TD]The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.[/TD] [TD]2025-04-04[/TD] [TD][9.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2798&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-2798]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2798')[/TD] [/TR] [TR] [TD]xwiki-contrib--jira [/TD] [TD]The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns an XML specifying a DOCTYPE pointing to a local file on the XWiki server host and displaying that file's content in one of the returned JIRA fields (such as the summary or description for example). The vulnerability has been patched in the JIRA Extension v8.6.5.[/TD] [TD]2025-04-03[/TD] [TD][7.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31487&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31487]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31487')[/TD] [/TR] [TR] [TD]YayCommerce--YayExtra [/TD] [TD]Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YayExtra: from n/a through 1.5.2.[/TD] [TD]2025-04-01[/TD] [TD][7.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31415&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H')[/TD] [TD][CVE-2025-31415]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31415')[/TD] [/TR] [TR] [TD]YesWiki--yeswiki [/TD] [TD]YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.[/TD] [TD]2025-04-01[/TD] [TD][8.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31131&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31131]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31131')[/TD] [/TR] [TR] [TD]zankover--Fami WooCommerce Compare [/TD] [TD]Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami WooCommerce Compare allows PHP Local File Inclusion.This issue affects Fami WooCommerce Compare: from n/a through 1.0.5.[/TD] [TD]2025-04-04[/TD] [TD][7.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31405&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31405]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31405')[/TD] [/TR] [TR] [TD]Zend--ZendTo [/TD] [TD]An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.[/TD] [TD]2025-04-05[/TD] [TD][10]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2021-47667&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H')[/TD] [TD][CVE-2021-47667]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-47667')[/TD] [/TR] [TR] [TD]zitadel--zitadel [/TD] [TD]Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check the expiration date of the JWT key when used for Authorization Grants. This allows an attacker with an expired key to obtain valid access tokens. This vulnerability does not affect the use of JWT Profile for OAuth 2.0 Client Authentication on the Token and Introspection endpoints, which correctly reject expired keys. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.[/TD] [TD]2025-03-31[/TD] [TD][8.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31123&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N')[/TD] [TD][CVE-2025-31123]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31123')[/TD] [/TR] [TR] [TD]ZoomIt--ZoomSounds - WordPress Wave Audio Player with Playlist [/TD] [TD]The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'seen' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. There are several other functions also vulnerable to missing authorization.[/TD] [TD]2025-04-05[/TD] [TD][8.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13776&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2024-13776]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13776')[/TD] [/TR] [/TABLE][/CENTER]

Back to top

Medium Vulnerabilities

[CENTER][TABLE] [TR] [TH]Primary Vendor -- Product[/TH] [TH]Description[/TH] [TH]Published[/TH] [TH]CVSS Score[/TH] [TH]Source Info[/TH] [/TR] [TR] [TD]1902756969--IKUN_Library [/TD] [TD]A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the component Borrow Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-05[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3305&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-3305]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3305')[/TD] [/TR] [TR] [TD]1clickmigration--1 Click WordPress Migration [/TD] [TD]Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32257&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-32257]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32257')[/TD] [/TR] [TR] [TD]6Storage--6Storage Rentals [/TD] [TD]Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.18.0.[/TD] [TD]2025-04-04[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32178&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32178]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32178')[/TD] [/TR] [TR] [TD]ABCdatos--AI Content Creator [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in ABCdatos AI Content Creator allows Cross Site Request Forgery. This issue affects AI Content Creator: from n/a through 1.2.6.[/TD] [TD]2025-04-04[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32247&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32247]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32247')[/TD] [/TR] [TR] [TD]ablancodev--Woocommerce Role Pricing [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Role Pricing allows Cross Site Request Forgery. This issue affects Woocommerce Role Pricing: from n/a through 3.5.5.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32271&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32271]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32271')[/TD] [/TR] [TR] [TD]acmemediakits--ACME Divi Modules [/TD] [TD]Missing Authorization vulnerability in acmemediakits ACME Divi Modules allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ACME Divi Modules: from n/a through 1.3.5.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31540&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31540]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31540')[/TD] [/TR] [TR] [TD]activecampaign--ActiveCampaign [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32136&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32136]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32136')[/TD] [/TR] [TR] [TD]adamwillhoeft--AI Content Pipelines: Content Engine + Analytics [/TD] [TD]The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.[/TD] [TD]2025-04-05[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2544&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-2544]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2544')[/TD] [/TR] [TR] [TD]Agency Dominion Inc.--Fusion [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion allows DOM-Based XSS. This issue affects Fusion: from n/a through 1.6.3.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31549&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31549]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31549')[/TD] [/TR] [TR] [TD]ahmadshyk--Gift Cards for WooCommerce [/TD] [TD]Missing Authorization vulnerability in ahmadshyk Gift Cards for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gift Cards for WooCommerce: from n/a through 1.5.8.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31781&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31781]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31781')[/TD] [/TR] [TR] [TD]aioseo--Broken Link Checker by AIOSEO Easily Fix/Monitor Internal and External links [/TD] [TD]The Broken Link Checker by AIOSEO - Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to SQL Injection via the 'orderBy' parameter in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.[/TD] [TD]2025-04-06[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1264&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-1264]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1264')[/TD] [/TR] [TR] [TD]Ajay--WebberZone Snippetz [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay WebberZone Snippetz allows Stored XSS. This issue affects WebberZone Snippetz: from n/a through 2.1.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31874&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31874]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31874')[/TD] [/TR] [TR] [TD]aleswebs--AdMail Multilingual Back in-Stock Notifier for WooCommerce [/TD] [TD]Missing Authorization vulnerability in aleswebs AdMail - Multilingual Back in-Stock Notifier for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AdMail - Multilingual Back in-Stock Notifier for WooCommerce: from n/a through 1.7.0.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32234&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32234]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32234')[/TD] [/TR] [TR] [TD]alextselegidis--Easy!Appointments [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments allows Cross Site Request Forgery. This issue affects Easy!Appointments: from n/a through 1.4.2.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31828&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31828]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31828')[/TD] [/TR] [TR] [TD]AlThemist--Lafka Plugin [/TD] [TD]The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_options_upload' AJAX function in all versions up to, and including, 7.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the theme option that overrides the site.[/TD] [TD]2025-04-05[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1233&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-1233]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1233')[/TD] [/TR] [TR] [TD]andreyazimov--Sheet2Site [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyazimov Sheet2Site allows Stored XSS. This issue affects Sheet2Site: from n/a through 1.0.18.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31762&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31762]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31762')[/TD] [/TR] [TR] [TD]Andy Stratton--Append Content [/TD] [TD]Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31780&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31780]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31780')[/TD] [/TR] [TR] [TD]Animesh Kumar--Advanced Speed Increaser [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser. This issue affects Advanced Speed Increaser: from n/a through 2.2.1.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31753&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31753]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31753')[/TD] [/TR] [TR] [TD]Anzar Ahmed--Display product variations dropdown on shop page [/TD] [TD]Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Display product variations dropdown on shop page: from n/a through 1.1.3.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32226&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32226]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32226')[/TD] [/TR] [TR] [TD]Anzar Ahmed--Ni WooCommerce Cost Of Goods [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32207&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32207]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32207')[/TD] [/TR] [TR] [TD]Anzar Ahmed--Ni WooCommerce Cost Of Goods [/TD] [TD]Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31826&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31826]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31826')[/TD] [/TR] [TR] [TD]Apache Software Foundation--Apache Answer [/TD] [TD]Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user. Users are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29868&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N')[/TD] [TD][CVE-2025-29868]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29868')[/TD] [/TR] [TR] [TD]Apache Software Foundation--Apache Camel [/TD] [TD]Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30177&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N')[/TD] [TD][CVE-2025-30177]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30177')[/TD] [/TR] [TR] [TD]Apache Software Foundation--Apache OFBiz [/TD] [TD]Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.[/TD] [TD]2025-04-01[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30676&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-30676]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30676')[/TD] [/TR] [TR] [TD]Aphotrax--Uptime Robot Plugin for WordPress [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows DOM-Based XSS. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31562&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31562]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31562')[/TD] [/TR] [TR] [TD]Aphotrax--Uptime Robot Plugin for WordPress [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows Cross Site Request Forgery. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31776&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31776]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31776')[/TD] [/TR] [TR] [TD]api-platform--core [/TD] [TD]API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2023-47639&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2023-47639]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47639')[/TD] [/TR] [TR] [TD]apimofficiel--Apimo Connector [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in apimofficiel Apimo Connector allows Cross Site Request Forgery. This issue affects Apimo Connector: from n/a through 2.6.3.1.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31602&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31602]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31602')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to read arbitrary file metadata.[/TD] [TD]2025-03-31[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24097&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24097]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24097')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30463&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30463]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30463')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to read sensitive location information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30470&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30470]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30470')[/TD] [/TR] [TR] [TD]apple -- ipados [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31191&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31191]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31191')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24239&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24239]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24239')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.[/TD] [TD]2025-03-31[/TD] [TD][5.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24157&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-24157]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24157')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24164&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24164]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24164')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24191&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24191]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24191')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24236&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24236]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24236')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.[/TD] [TD]2025-03-31[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24248&vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-24248]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24248')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24262&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24262]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24262')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24278&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24278]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24278')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24280&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24280]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24280')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24281&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24281]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24281')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24282&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24282]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24282')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30435&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30435]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30435')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30451&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30451]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30451')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31187&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-31187]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31187')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24240&vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24240]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24240')[/TD] [/TR] [TR] [TD]apple -- macos [/TD] [TD]This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][4.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24242&vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24242]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24242')[/TD] [/TR] [TR] [TD]apple -- safari [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30467&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-30467]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30467')[/TD] [/TR] [TR] [TD]apple -- xcode [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24226&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24226]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24226')[/TD] [/TR] [TR] [TD]apple -- xcode [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30441&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-30441]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30441')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a website may leak sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24192&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24192]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24192')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24198&vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-24198]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24198')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.[/TD] [TD]2025-03-31[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24208&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-24208]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24208')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.[/TD] [TD]2025-03-31[/TD] [TD][6.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31192&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L')[/TD] [TD][CVE-2025-31192]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31192')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24202&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24202]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24202')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]An authorization issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24205&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24205]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24205')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]A logging issue was addressed with improved data redaction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24283&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24283]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24283')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.[/TD] [TD]2025-03-31[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30428&vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L')[/TD] [TD][CVE-2025-30428]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30428')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.[/TD] [TD]2025-03-31[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30434&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-30434]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30434')[/TD] [/TR] [TR] [TD]Apple--iOS and iPadOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An attacker with physical access to a locked device may be able to view sensitive user information.[/TD] [TD]2025-03-31[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30439&vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30439]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30439')[/TD] [/TR] [TR] [TD]Apple--iPadOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24203&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24203]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24203')[/TD] [/TR] [TR] [TD]Apple--iPadOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24215&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24215]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24215')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][6.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24272&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2025-24272]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24272')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app with root privileges may be able to modify the contents of system files.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30446&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H')[/TD] [TD][CVE-2025-30446]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30446')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause a denial-of-service.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24199&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-24199]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24199')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24218&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24218]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24218')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote attacker may be able to cause unexpected app termination or heap corruption.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24235&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-24235]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24235')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24261&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-24261]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24261')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24276&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24276]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24276')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30443&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30443]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30443')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30450&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30450]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30450')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30455&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30455]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30455')[/TD] [/TR] [TR] [TD]Apple--macOS [/TD] [TD]This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24279&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-24279]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24279')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A logic issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may result in the disclosure of process memory.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24194&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24194]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24194')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with improved checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24212&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-24212]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24212')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A path handling issue was addressed with improved validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30429&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30429]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30429')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sonoma 14.7.5. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.[/TD] [TD]2025-03-31[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30432&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L')[/TD] [TD][CVE-2025-30432]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30432')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing a maliciously crafted font may result in the disclosure of process memory.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24182&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24182]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24182')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A logic error was addressed with improved error handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Parsing an image may lead to disclosure of user information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24210&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24210]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24210')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A privacy issue was addressed by not logging contents of text fields. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24214&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24214]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24214')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24217&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24217]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24217')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted font may result in the disclosure of process memory.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24244&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24244]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24244')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30438&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-30438]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30438')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]The issue was resolved by sanitizing logging This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30447&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30447]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30447')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. A malicious app may be able to access private information.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30454&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-30454]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30454')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24216&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-24216]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24216')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]This issue was addressed through improved state management. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to track users in Safari private browsing mode.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30425&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-30425]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30425')[/TD] [/TR] [TR] [TD]Apple--tvOS [/TD] [TD]A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30427&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-30427]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30427')[/TD] [/TR] [TR] [TD]appointify--Appointify [/TD] [TD]Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify allows Upload a Web Shell to a Web Server. This issue affects Appointify: from n/a through 1.0.8.[/TD] [TD]2025-03-31[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31577&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31577]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31577')[/TD] [/TR] [TR] [TD]appointy--Appointy Appointment Scheduler [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in appointy Appointy Appointment Scheduler allows Cross Site Request Forgery. This issue affects Appointy Appointment Scheduler: from n/a through 4.2.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31601&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31601]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31601')[/TD] [/TR] [TR] [TD]Arni Cinco--Subscription Form for Feedblitz [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arni Cinco Subscription Form for Feedblitz allows Stored XSS. This issue affects Subscription Form for Feedblitz: from n/a through 1.0.9.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31745&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31745]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31745')[/TD] [/TR] [TR] [TD]Arni Cinco--WPCargo Track & Trace [/TD] [TD]Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPCargo Track & Trace: from n/a through 7.0.6.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31609&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31609]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31609')[/TD] [/TR] [TR] [TD]Arrow Plugins--Arrow Custom Feed for Twitter [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Custom Feed for Twitter allows Stored XSS. This issue affects Arrow Custom Feed for Twitter: from n/a through 1.5.3.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31897&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31897]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31897')[/TD] [/TR] [TR] [TD]Ashish Ajani--WP Church Donation [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Church Donation allows Cross Site Request Forgery.This issue affects WP Church Donation: from n/a through 1.7.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31410&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31410]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31410')[/TD] [/TR] [TR] [TD]Ashish Ajani--WP Simple HTML Sitemap [/TD] [TD]Missing Authorization vulnerability in Ashish Ajani WP Simple HTML Sitemap allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Simple HTML Sitemap: from n/a through 3.2.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31822&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-31822]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31822')[/TD] [/TR] [TR] [TD]Astoundify--WP Modal Popup with Cookie Integration [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration allows Stored XSS. This issue affects WP Modal Popup with Cookie Integration: from n/a through 2.4.[/TD] [TD]2025-04-01[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31772&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31772]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31772')[/TD] [/TR] [TR] [TD]Ateeq Rafeeq--RepairBuddy [/TD] [TD]Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32277&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32277]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32277')[/TD] [/TR] [TR] [TD]aThemeArt--News, Magazine and Blog Elements [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt News, Magazine and Blog Elements allows Stored XSS. This issue affects News, Magazine and Blog Elements: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31740&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31740]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31740')[/TD] [/TR] [TR] [TD]AWS--AWS Serverless Application Model Command Line Interface [/TD] [TD]When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container. Users should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3047&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-3047]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3047')[/TD] [/TR] [TR] [TD]AWS--AWS Serverless Application Model Command Line Interface [/TD] [TD]After completing a build with AWS Serverless Application Model Command Line Interface (SAM CLI) which include symlinks, the content of those symlinks are copied to the cache of the local workspace as regular files or directories. As a result, a user who does not have access to those symlinks outside of the Docker container would now have access via the local workspace. Users should upgrade to version 1.134.0 and ensure any forked or derivative code is patched to incorporate the new fixes. After upgrading, users must re-build their applications using the sam build --use-container to update the symlinks.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3048&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-3048]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3048')[/TD] [/TR] [TR] [TD]axew3--WP w3all phpBB [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32274&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32274]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32274')[/TD] [/TR] [TR] [TD]Ays Pro--Secure Copy Content Protection and Content Locking [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.5.1.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32133&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32133]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32133')[/TD] [/TR] [TR] [TD]bdthemes--Ultimate Store Kit Elementor Addons [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32184&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32184]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32184')[/TD] [/TR] [TR] [TD]BeastThemes--Clockinator Lite [/TD] [TD]Missing Authorization vulnerability in BeastThemes Clockinator Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Clockinator Lite: from n/a through 1.0.7.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31777&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31777]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31777')[/TD] [/TR] [TR] [TD]Beee--ACF City Selector [/TD] [TD]Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector allows Retrieve Embedded Sensitive Data. This issue affects ACF City Selector: from n/a through 1.16.0.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31832&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31832]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31832')[/TD] [/TR] [TR] [TD]BeRocket--Sequential Order Numbers for WooCommerce [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32263&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32263]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32263')[/TD] [/TR] [TR] [TD]Best WP Developer--BWD Elementor Addons [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer BWD Elementor Addons allows DOM-Based XSS. This issue affects BWD Elementor Addons: from n/a through 4.3.20.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32189&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32189]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32189')[/TD] [/TR] [TR] [TD]bigboomdesign--Big Boom Directory [/TD] [TD]The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-03[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-13673&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2024-13673]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-13673')[/TD] [/TR] [TR] [TD]BinaryCarpenter--Free Woocommerce Product Table View [/TD] [TD]Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31758&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-31758]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31758')[/TD] [/TR] [TR] [TD]BinaryCarpenter--Free Woocommerce Product Table View [/TD] [TD]Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31757&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31757]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31757')[/TD] [/TR] [TR] [TD]Binsaifullah--Posten [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binsaifullah Posten allows DOM-Based XSS. This issue affects Posten: from n/a through 0.0.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31790&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31790]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31790')[/TD] [/TR] [TR] [TD]blackandwhitedigital--WP Genealogy Your Family History Website [/TD] [TD]Missing Authorization vulnerability in blackandwhitedigital WP Genealogy - Your Family History Website allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Genealogy - Your Family History Website: from n/a through 0.1.9.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32252&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32252]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32252')[/TD] [/TR] [TR] [TD]blazethemes--News Kit Elementor Addons [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons allows Stored XSS. This issue affects News Kit Elementor Addons: from n/a through 1.3.1.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32196&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32196]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32196')[/TD] [/TR] [TR] [TD]Blocksera--Cryptocurrency Widgets Pack [/TD] [TD]Missing Authorization vulnerability in Blocksera Cryptocurrency Widgets Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cryptocurrency Widgets Pack: from n/a through 2.0.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31539&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31539]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31539')[/TD] [/TR] [TR] [TD]bobcares_plugins--Gift Certificate Creator [/TD] [TD]The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'receip_address' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.[/TD] [TD]2025-04-02[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2483&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-2483]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2483')[/TD] [/TR] [TR] [TD]BoldGrid--Sprout Clients [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients allows Stored XSS. This issue affects Sprout Clients: from n/a through 3.2.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31797&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31797]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31797')[/TD] [/TR] [TR] [TD]Bookingor--Bookingor [/TD] [TD]Missing Authorization vulnerability in Bookingor Bookingor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bookingor: from n/a through 1.0.6.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32231&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32231]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32231')[/TD] [/TR] [TR] [TD]BooSpot--Boo Recipes [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31759&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31759]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31759')[/TD] [/TR] [TR] [TD]Boot Div--WP Sitemap [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boot Div WP Sitemap allows Stored XSS. This issue affects WP Sitemap: from n/a through 1.0.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31733&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31733]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31733')[/TD] [/TR] [TR] [TD]Bowo--Variable Inspector [/TD] [TD]Missing Authorization vulnerability in Bowo Variable Inspector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Variable Inspector: from n/a through 2.6.3.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32229&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32229]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32229')[/TD] [/TR] [TR] [TD]bPlugins--B Blocks - The ultimate block collection [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks - The ultimate block collection allows Stored XSS. This issue affects B Blocks - The ultimate block collection: from n/a through 2.0.0.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32173&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32173]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32173')[/TD] [/TR] [TR] [TD]Brady Vercher--Cue [/TD] [TD]Missing Authorization vulnerability in Brady Vercher Cue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cue: from n/a through 2.4.4.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31787&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31787]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31787')[/TD] [/TR] [TR] [TD]brainvireinfo--Export All Post Meta [/TD] [TD]Missing Authorization vulnerability in brainvireinfo Export All Post Meta allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Export All Post Meta: from n/a through 1.2.1.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31856&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31856]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31856')[/TD] [/TR] [TR] [TD]Brice Capobianco--WP Plugin Info Card [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brice Capobianco WP Plugin Info Card allows DOM-Based XSS. This issue affects WP Plugin Info Card: from n/a through 5.2.5.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31835&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31835]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31835')[/TD] [/TR] [TR] [TD]Broadstreet--Broadstreet [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Broadstreet Broadstreet allows Cross Site Request Forgery. This issue affects Broadstreet: from n/a through 1.51.1.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32270&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32270]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32270')[/TD] [/TR] [TR] [TD]C. Johnson--Footnotes for WordPress [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnotes for WordPress allows Stored XSS. This issue affects Footnotes for WordPress: from n/a through 2016.1230.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31735&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31735]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31735')[/TD] [/TR] [TR] [TD]Cal.com--Cal.com [/TD] [TD]Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com allows Stored XSS. This issue affects Cal.com: from n/a through 1.0.0.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31604&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31604]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31604')[/TD] [/TR] [TR] [TD]carperfer--CoverManager [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in carperfer CoverManager allows Stored XSS. This issue affects CoverManager: from n/a through 0.0.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31620&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31620]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31620')[/TD] [/TR] [TR] [TD]CartBoss--SMS Abandoned Cart Recovery CartBoss [/TD] [TD]Missing Authorization vulnerability in CartBoss SMS Abandoned Cart Recovery ✦ CartBoss allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SMS Abandoned Cart Recovery ✦ CartBoss: from n/a through 4.1.2.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31865&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31865]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31865')[/TD] [/TR] [TR] [TD]Caspio Bridge--Custom Database Applications by Caspio [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Caspio Bridge Custom Database Applications by Caspio allows DOM-Based XSS. This issue affects Custom Database Applications by Caspio: from n/a through 2.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31559&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31559]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31559')[/TD] [/TR] [TR] [TD]cedcommerce--Ship Per Product [/TD] [TD]Missing Authorization vulnerability in cedcommerce Ship Per Product allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ship Per Product: from n/a through 2.1.0.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31773&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-31773]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31773')[/TD] [/TR] [TR] [TD]ChainMaker--chainmaker-go [/TD] [TD]In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations on a map, leading to a panic.[/TD] [TD]2025-04-06[/TD] [TD][4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-58132&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L')[/TD] [TD][CVE-2024-58132]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-58132')[/TD] [/TR] [TR] [TD]ChainMaker--chainmaker-go [/TD] [TD]In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a map are mishandled. Creating other logs simultaneously can lead to a read-write conflict and panic.[/TD] [TD]2025-04-06[/TD] [TD][4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-58133&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L')[/TD] [TD][CVE-2024-58133]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-58133')[/TD] [/TR] [TR] [TD]Chatwee--Chat by Chatwee [/TD] [TD]Missing Authorization vulnerability in Chatwee Chat by Chatwee allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Chat by Chatwee: from n/a through 2.1.3.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31596&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31596]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31596')[/TD] [/TR] [TR] [TD]checklistcom--Checklist [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Checklist allows Stored XSS. This issue affects Checklist: from n/a through 1.1.9.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31538&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31538]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31538')[/TD] [/TR] [TR] [TD]cheesefather--Botnet Attack Blocker [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botnet Attack Blocker allows Stored XSS. This issue affects Botnet Attack Blocker: from n/a through 2.0.0.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31893&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31893]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31893')[/TD] [/TR] [TR] [TD]Cisco--Cisco Prime Infrastructure [/TD] [TD]A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.[/TD] [TD]2025-04-02[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-20120&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-20120]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-20120')[/TD] [/TR] [TR] [TD]Cisco--Cisco Prime Infrastructure [/TD] [TD]A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials. {{value}} ["%7b%7bvalue%7d%7d"])}]][/TD] [TD]2025-04-02[/TD] [TD][4.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-20203&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-20203]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-20203')[/TD] [/TR] [TR] [TD]Clearbit--Clearbit Reveal [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal allows Cross Site Request Forgery. This issue affects Clearbit Reveal: from n/a through 1.0.6.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31785&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31785]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31785')[/TD] [/TR] [TR] [TD]CleverReach--Official CleverReach Plugin for WooCommerce [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce allows Cross Site Request Forgery. This issue affects Official CleverReach Plugin for WooCommerce: from n/a through 3.4.3.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32241&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32241]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32241')[/TD] [/TR] [TR] [TD]CloudRedux--Product Notices for WooCommerce [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in CloudRedux Product Notices for WooCommerce allows Cross Site Request Forgery. This issue affects Product Notices for WooCommerce: from n/a through 1.3.3.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31807&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31807]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31807')[/TD] [/TR] [TR] [TD]code-projects--Bus Reservation System [/TD] [TD]A vulnerability was found in code-projects Bus Reservation System 1.0 and classified as critical. Affected by this issue is the function Login of the component Login Form. The manipulation of the argument Str1 leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3139&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3139]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3139')[/TD] [/TR] [TR] [TD]code-projects--College Management System [/TD] [TD]A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The manipulation of the argument profile_image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2973&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2973]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2973')[/TD] [/TR] [TR] [TD]code-projects--Hospital Management System [/TD] [TD]A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3206&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3206]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3206')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /birthing_form.php. The manipulation of the argument birth_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3207&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3207]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3207')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3208&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3208]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3208')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_patient.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3209&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3209]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3209')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3210&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3210]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3210')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3211&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3211]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3211')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dental_form.php. The manipulation of the argument itr_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3243&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3243]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3243')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-05[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3303&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3303]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3303')[/TD] [/TR] [TR] [TD]code-projects--Patient Record Management System [/TD] [TD]A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_not.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-05[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3304&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3304]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3304')[/TD] [/TR] [TR] [TD]code-projects--Payroll Management System [/TD] [TD]A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /delete.php. The manipulation of the argument emp_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2984&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2984]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2984')[/TD] [/TR] [TR] [TD]code-projects--Payroll Management System [/TD] [TD]A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. The manipulation of the argument deduction leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2985&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2985]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2985')[/TD] [/TR] [TR] [TD]code-projects--Payroll Management System [/TD] [TD]A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_account.php. The manipulation of the argument salary_rate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3038&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3038]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3038')[/TD] [/TR] [TR] [TD]code-projects--Payroll Management System [/TD] [TD]A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_employee.php. The manipulation of the argument lname/fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3039&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3039]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3039')[/TD] [/TR] [TR] [TD]code-projects--Payroll Management System [/TD] [TD]A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3134&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3134]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3134')[/TD] [/TR] [TR] [TD]code-projects--Product Management System [/TD] [TD]A vulnerability classified as critical was found in code-projects Product Management System 1.0. This vulnerability affects the function search_item of the component Search Product Menu. The manipulation of the argument target leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3166&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3166]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3166')[/TD] [/TR] [TR] [TD]CodeAstro--Car Rental System [/TD] [TD]A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3204&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3204]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3204')[/TD] [/TR] [TR] [TD]CodeAstro--Student Grading System [/TD] [TD]A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3205&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3205]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3205')[/TD] [/TR] [TR] [TD]CodeYatri--Gutenify [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeYatri Gutenify allows Stored XSS. This issue affects Gutenify: from n/a through 1.4.9.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32168&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32168]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32168')[/TD] [/TR] [TR] [TD]ComMotion--Course Booking System [/TD] [TD]Missing Authorization vulnerability in ComMotion Course Booking System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Course Booking System: from n/a through 6.0.5.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32253&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-32253]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32253')[/TD] [/TR] [TR] [TD]contempoinc--Contempo Real Estate Core [/TD] [TD]The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-01[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2906&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-2906]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2906')[/TD] [/TR] [TR] [TD]ContentBot.ai--ContentBot AI Writer [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer allows Stored XSS. This issue affects ContentBot AI Writer: from n/a through 1.2.4.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31818&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31818]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31818')[/TD] [/TR] [TR] [TD]ContentMX--ContentMX Content Publisher [/TD] [TD]Missing Authorization vulnerability in ContentMX ContentMX Content Publisher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentMX Content Publisher: from n/a through 1.0.6.[/TD] [TD]2025-03-31[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31555&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31555]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31555')[/TD] [/TR] [TR] [TD]crazycric--Ultimate Live Cricket WordPress Lite [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crazycric Ultimate Live Cricket WordPress Lite allows Stored XSS. This issue affects Ultimate Live Cricket WordPress Lite: from n/a through 1.4.2.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31597&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31597]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31597')[/TD] [/TR] [TR] [TD]CreativeMindsSolutions--CM Header and Footer [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Header and Footer allows Stored XSS. This issue affects CM Header and Footer: from n/a through 1.2.4.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31091&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31091]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31091')[/TD] [/TR] [TR] [TD]Cristin Lvaque--s2Member [/TD] [TD]Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.[/TD] [TD]2025-04-04[/TD] [TD][4.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32137&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-32137]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32137')[/TD] [/TR] [TR] [TD]CRM Perks--WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Cross Site Request Forgery. This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through 1.1.3.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32269&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32269]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32269')[/TD] [/TR] [TR] [TD]Crocoblock--JetSmartFilters [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters allows DOM-Based XSS.This issue affects JetSmartFilters: from n/a through 3.6.3.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30963&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30963]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30963')[/TD] [/TR] [TR] [TD]Daniel Floeter--Hyperlink Group Block [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31885&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31885]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31885')[/TD] [/TR] [TR] [TD]Data443 Risk Migitation, Inc.--Posts Footer Manager [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Posts Footer Manager allows Stored XSS. This issue affects Posts Footer Manager: from n/a through 2.2.0.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32130&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32130]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32130')[/TD] [/TR] [TR] [TD]Data443 Risk Migitation, Inc.--Welcome Bar [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Welcome Bar allows Stored XSS. This issue affects Welcome Bar: from n/a through 2.0.4.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32129&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32129]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32129')[/TD] [/TR] [TR] [TD]David Lingren--Media Library Assistant [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media Library Assistant allows Stored XSS. This issue affects Media Library Assistant: from n/a through 3.24.[/TD] [TD]2025-03-31[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31627&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31627]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31627')[/TD] [/TR] [TR] [TD]davidpaulsson--byBrick Accordion [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpaulsson byBrick Accordion allows Stored XSS. This issue affects byBrick Accordion: from n/a through 1.0.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31621&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31621]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31621')[/TD] [/TR] [TR] [TD]dbejean--Advanced Search by My Solr Server [/TD] [TD]The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the 'MySolrServerSettings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.[/TD] [TD]2025-04-02[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3099&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-3099]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3099')[/TD] [/TR] [TR] [TD]DEJAN--Hypotext [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEJAN Hypotext allows Stored XSS. This issue affects Hypotext: from n/a through 1.0.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31761&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31761]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31761')[/TD] [/TR] [TR] [TD]Dell--Wyse Management Suite Repository [/TD] [TD]Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution[/TD] [TD]2025-04-02[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27692&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-27692]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27692')[/TD] [/TR] [TR] [TD]Dell--Wyse Management Suite [/TD] [TD]Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.[/TD] [TD]2025-04-02[/TD] [TD][6.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29982&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H')[/TD] [TD][CVE-2025-29982]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29982')[/TD] [/TR] [TR] [TD]Dell--Wyse Management Suite [/TD] [TD]Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.[/TD] [TD]2025-04-02[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27694&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-27694]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27694')[/TD] [/TR] [TR] [TD]Dell--Wyse Management Suite [/TD] [TD]Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.[/TD] [TD]2025-04-02[/TD] [TD][4.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27693&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-27693]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27693')[/TD] [/TR] [TR] [TD]Denra.com--WP Date and Time Shortcode [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Denra.com WP Date and Time Shortcode allows Stored XSS. This issue affects WP Date and Time Shortcode: from n/a through 2.6.7.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31590&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31590]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31590')[/TD] [/TR] [TR] [TD]designinvento--DirectoryPress [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in designinvento DirectoryPress allows Cross Site Request Forgery. This issue affects DirectoryPress: from n/a through 3.6.19.[/TD] [TD]2025-04-04[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32249&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32249]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32249')[/TD] [/TR] [TR] [TD]designnbuy--DesignO [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in designnbuy DesignO allows Cross Site Request Forgery. This issue affects DesignO: from n/a through 2.2.0.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31600&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31600]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31600')[/TD] [/TR] [TR] [TD]devscred--Design Blocks [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks allows Stored XSS. This issue affects Design Blocks: from n/a through 1.2.2.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31815&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31815]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31815')[/TD] [/TR] [TR] [TD]devscred--ShopCred [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred allows DOM-Based XSS. This issue affects ShopCred: from n/a through 1.2.8.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31829&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31829]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31829')[/TD] [/TR] [TR] [TD]devsoftbaltic--SurveyJS [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devsoftbaltic SurveyJS allows Stored XSS. This issue affects SurveyJS: from n/a through 1.12.20.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32167&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32167]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32167')[/TD] [/TR] [TR] [TD]devsoftbaltic--SurveyJS [/TD] [TD]Missing Authorization vulnerability in devsoftbaltic SurveyJS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects SurveyJS: from n/a through 1.12.20.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32256&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-32256]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32256')[/TD] [/TR] [TR] [TD]digireturn--DN Footer Contacts [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts allows Cross Site Request Forgery. This issue affects DN Footer Contacts: from n/a through 1.8.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31839&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31839]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31839')[/TD] [/TR] [TR] [TD]digireturn--Simple Fixed Notice [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in digireturn Simple Fixed Notice allows Cross Site Request Forgery. This issue affects Simple Fixed Notice: from n/a through 1.6.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31840&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31840]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31840')[/TD] [/TR] [TR] [TD]DigitalCourt--Marketer Addons [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons allows Stored XSS. This issue affects Marketer Addons: from n/a through 1.0.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31730&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31730]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31730')[/TD] [/TR] [TR] [TD]Dimitri Grassi--Salon booking system [/TD] [TD]Missing Authorization vulnerability in Dimitri Grassi Salon booking system allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon booking system: from n/a through 10.10.7.[/TD] [TD]2025-04-04[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32220&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-32220]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32220')[/TD] [/TR] [TR] [TD]djangoproject--Django [/TD] [TD]An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.LogoutView, and django.views.i18n.set_language are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.[/TD] [TD]2025-04-02[/TD] [TD][5.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27556&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L')[/TD] [TD][CVE-2025-27556]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27556')[/TD] [/TR] [TR] [TD]Dmitry V. (CEO of "UKR Solution")--Barcode Generator for WooCommerce [/TD] [TD]Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Barcode Generator for WooCommerce: from n/a through 2.0.4.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31879&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31879]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31879')[/TD] [/TR] [TR] [TD]Dmitry V. (CEO of "UKR Solution")--UPC/EAN/GTIN Code Generator [/TD] [TD]Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects UPC/EAN/GTIN Code Generator: from n/a through 2.0.2.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31878&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31878]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31878')[/TD] [/TR] [TR] [TD]DobsonDev--DobsonDev Shortcodes [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DobsonDev DobsonDev Shortcodes allows Stored XSS. This issue affects DobsonDev Shortcodes: from n/a through 2.1.12.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31754&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31754]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31754')[/TD] [/TR] [TR] [TD]docxpresso--Docxpresso [/TD] [TD]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso allows Absolute Path Traversal. This issue affects Docxpresso: from n/a through 2.6.[/TD] [TD]2025-04-03[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31554&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-31554]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31554')[/TD] [/TR] [TR] [TD]doit--Breaking News WP [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31751&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31751]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31751')[/TD] [/TR] [TR] [TD]doit--Breaking News WP [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in doit Breaking News WP allows Stored XSS. This issue affects Breaking News WP: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31750&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31750]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31750')[/TD] [/TR] [TR] [TD]DraftPress Team--Follow Us Badges [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DraftPress Team Follow Us Badges allows Stored XSS. This issue affects Follow Us Badges: from n/a through 3.1.11.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31804&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31804]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31804')[/TD] [/TR] [TR] [TD]Drupal--AI (Artificial Intelligence) [/TD] [TD]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.[/TD] [TD]2025-03-31[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31693&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-31693]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31693')[/TD] [/TR] [TR] [TD]Drupal--Drupal Admin LTE theme [/TD] [TD]Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: [I].[/I].[/TD] [TD]2025-03-31[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3062&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3062]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3062')[/TD] [/TR] [TR] [TD]Drupal--Drupal core [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.[/TD] [TD]2025-03-31[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3057&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-3057]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3057')[/TD] [/TR] [TR] [TD]Drupal--Material Admin [/TD] [TD]Vulnerability in Drupal Material Admin.This issue affects Material Admin: [I].[/I].[/TD] [TD]2025-03-31[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3061&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2025-3061]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3061')[/TD] [/TR] [TR] [TD]Drupal--Obfuscate [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.[/TD] [TD]2025-04-02[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3130&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-3130]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3130')[/TD] [/TR] [TR] [TD]dxladner--Client Showcase [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase allows Stored XSS. This issue affects Client Showcase: from n/a through 1.2.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31737&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31737]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31737')[/TD] [/TR] [TR] [TD]Ecwid by Lightspeed Ecommerce Shopping Cart--Ecwid Shopping Cart [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart allows Stored XSS. This issue affects Ecwid Shopping Cart: from n/a through 7.0.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32195&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32195]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32195')[/TD] [/TR] [TR] [TD]element-hq--element-x-android [/TD] [TD]Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25.03.3, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This vulnerability is fixed in 25.03.4.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31127&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31127]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31127')[/TD] [/TR] [TR] [TD]element-hq--element-x-ios [/TD] [TD]Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This vulnerability is fixed in 25.03.8.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31126&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31126]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31126')[/TD] [/TR] [TR] [TD]ELEXtensions--ELEX WooCommerce Request a Quote [/TD] [TD]Subscriber Broken Access Control in ELEX WooCommerce Request a Quote <= 2.3.3 versions.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31406&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31406]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31406')[/TD] [/TR] [TR] [TD]elfsight--Elfsight Testimonials Slider [/TD] [TD]Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.[/TD] [TD]2025-03-31[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31584&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31584]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31584')[/TD] [/TR] [TR] [TD]elfsight--Elfsight Testimonials Slider [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider allows Stored XSS. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.[/TD] [TD]2025-03-31[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31587&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31587]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31587')[/TD] [/TR] [TR] [TD]elfsight--Elfsight Testimonials Slider [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in elfsight Elfsight Testimonials Slider allows Cross Site Request Forgery. This issue affects Elfsight Testimonials Slider: from n/a through 1.0.1.[/TD] [TD]2025-03-31[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31588&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31588]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31588')[/TD] [/TR] [TR] [TD]elunez--eladmin [/TD] [TD]A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConnect of the component Maintenance Management Module. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3250&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-3250]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3250')[/TD] [/TR] [TR] [TD]Enalean--tuleap [/TD] [TD]Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition 16.5-6 and 16.4-10.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30209&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-30209]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30209')[/TD] [/TR] [TR] [TD]Enalean--tuleap [/TD] [TD]Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The vulnerability is fixed in Tuleap Community Edition 16.5.99.1741784483 and Tuleap Enterprise Edition 16.5-3 and 16.4-8.[/TD] [TD]2025-03-31[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29766&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-29766]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29766')[/TD] [/TR] [TR] [TD]Enalean--tuleap [/TD] [TD]Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742306712 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.[/TD] [TD]2025-03-31[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29929&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-29929]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29929')[/TD] [/TR] [TR] [TD]Enalean--tuleap [/TD] [TD]Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30155&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-30155]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30155')[/TD] [/TR] [TR] [TD]Enalean--tuleap [/TD] [TD]Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.[/TD] [TD]2025-03-31[/TD] [TD][4.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30203&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L')[/TD] [TD][CVE-2025-30203]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30203')[/TD] [/TR] [TR] [TD]Eniture Technology--Pallet Packaging for WooCommerce [/TD] [TD]Missing Authorization vulnerability in Eniture Technology Pallet Packaging for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pallet Packaging for WooCommerce: from n/a through 1.1.15.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22285&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-22285]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22285')[/TD] [/TR] [TR] [TD]enituretechnology--Residential Address Detection [/TD] [TD]Missing Authorization vulnerability in enituretechnology Residential Address Detection allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Residential Address Detection: from n/a through 2.5.4.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30916&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-30916]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30916')[/TD] [/TR] [TR] [TD]enituretechnology--Small Package Quotes Worldwide Express Edition [/TD] [TD]Missing Authorization vulnerability in enituretechnology Small Package Quotes - Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes - Worldwide Express Edition: from n/a through 5.2.19.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30915&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-30915]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30915')[/TD] [/TR] [TR] [TD]ERA404--StaffList [/TD] [TD]Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList allows Retrieve Embedded Sensitive Data. This issue affects StaffList: from n/a through 3.2.6.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32255&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-32255]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32255')[/TD] [/TR] [TR] [TD]ERA404--StaffList [/TD] [TD]Missing Authorization vulnerability in ERA404 StaffList allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects StaffList: from n/a through 3.2.6.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32232&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32232]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32232')[/TD] [/TR] [TR] [TD]Erez Hadas-Sonnenschein--Smartarget Popup [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup allows Stored XSS. This issue affects Smartarget Popup: from n/a through 1.4.[/TD] [TD]2025-04-01[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31853&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31853]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31853')[/TD] [/TR] [TR] [TD]ESAFENET--CDG [/TD] [TD]A vulnerability, which was classified as critical, was found in ESAFENET CDG 3. Affected is an unknown function of the file /CDGServer3/UserAjax. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3003&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3003]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3003')[/TD] [/TR] [TR] [TD]eventbee--Eventbee RSVP Widget [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eventbee Eventbee RSVP Widget allows DOM-Based XSS. This issue affects Eventbee RSVP Widget: from n/a through 1.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31838&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31838]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31838')[/TD] [/TR] [TR] [TD]EXEIdeas International--WP AutoKeyword [/TD] [TD]Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP AutoKeyword: from n/a through 1.0.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31870&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31870]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31870')[/TD] [/TR] [TR] [TD]ExpressTech Systems--Gutena Kit Gutenberg Blocks and Templates [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Systems Gutena Kit - Gutenberg Blocks and Templates allows Stored XSS. This issue affects Gutena Kit - Gutenberg Blocks and Templates: from n/a through 2.0.7.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31805&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31805]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31805')[/TD] [/TR] [TR] [TD]Extend Themes--Colibri Page Builder [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder allows Stored XSS. This issue affects Colibri Page Builder: from n/a through 1.0.319.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32185&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32185]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32185')[/TD] [/TR] [TR] [TD]Fahad Mahmood--WP Docs [/TD] [TD]Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Docs: from n/a through n/a.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31417&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31417]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31417')[/TD] [/TR] [TR] [TD]Fast Simon--Search, Filters & Merchandising for WooCommerce [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fast Simon Search, Filters & Merchandising for WooCommerce allows Stored XSS. This issue affects Search, Filters & Merchandising for WooCommerce: from n/a through 3.0.57.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32181&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32181]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32181')[/TD] [/TR] [TR] [TD]fbtemplates--Nemesis All-in-One [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fbtemplates Nemesis All-in-One allows Stored XSS. This issue affects Nemesis All-in-One: from n/a through 1.1.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31849&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31849]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31849')[/TD] [/TR] [TR] [TD]fcba_zzm--ics-park Smart Park Management System [/TD] [TD]A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3135&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3135]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3135')[/TD] [/TR] [TR] [TD]Feedbucket--Feedbucket Website Feedback Tool [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket - Website Feedback Tool allows Cross Site Request Forgery. This issue affects Feedbucket - Website Feedback Tool: from n/a through 1.0.6.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31859&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31859]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31859')[/TD] [/TR] [TR] [TD]Filtr8--Easy Magazine [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filtr8 Easy Magazine allows DOM-Based XSS. This issue affects Easy Magazine: from n/a through 2.1.13.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31741&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31741]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31741')[/TD] [/TR] [TR] [TD]FISCO-BCOS--FISCO-BCOS [/TD] [TD]FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a large min_seal_time value) joins a blockchain network.[/TD] [TD]2025-04-06[/TD] [TD][4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-58131&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L')[/TD] [TD][CVE-2024-58131]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-58131')[/TD] [/TR] [TR] [TD]flomei--Simple-Audioplayer [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flomei Simple-Audioplayer allows Stored XSS. This issue affects Simple-Audioplayer: from n/a through 1.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31607&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31607]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31607')[/TD] [/TR] [TR] [TD]formsintegrations--Integration of Zoho CRM and Contact Form 7 [/TD] [TD]URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.[/TD] [TD]2025-04-01[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31821&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31821]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31821')[/TD] [/TR] [TR] [TD]Fortinet--FortiNDR [/TD] [TD]A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.[/TD] [TD]2025-03-31[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2023-33302&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2023-33302]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33302')[/TD] [/TR] [TR] [TD]Frank P. Walentynowicz--FPW Category Thumbnails [/TD] [TD]Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FPW Category Thumbnails: from n/a through 1.9.5.[/TD] [TD]2025-04-03[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31841&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31841]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31841')[/TD] [/TR] [TR] [TD]freedesktop--Poppler [/TD] [TD]A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.[/TD] [TD]2025-04-05[/TD] [TD][4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32364&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-32364]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32364')[/TD] [/TR] [TR] [TD]freedesktop--Poppler [/TD] [TD]Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.[/TD] [TD]2025-04-05[/TD] [TD][4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32365&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-32365]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32365')[/TD] [/TR] [TR] [TD]freetobook--Freetobook Responsive Widget [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget allows Cross Site Request Forgery. This issue affects Freetobook Responsive Widget: from n/a through 1.1.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32273&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32273]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32273')[/TD] [/TR] [TR] [TD]fromdoppler--Doppler Forms [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32165&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32165]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32165')[/TD] [/TR] [TR] [TD]fumiao--opencms [/TD] [TD]A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.[/TD] [TD]2025-04-06[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3317&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-3317]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3317')[/TD] [/TR] [TR] [TD]FunnelCockpit--FunnelCockpit [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit allows Stored XSS. This issue affects FunnelCockpit: from n/a through 1.4.2.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32132&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32132]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32132')[/TD] [/TR] [TR] [TD]Gagan Deep Singh--PostmarkApp Email Integrator [/TD] [TD]Missing Authorization vulnerability in Gagan Deep Singh PostmarkApp Email Integrator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PostmarkApp Email Integrator: from n/a through 2.4.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31576&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31576]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31576')[/TD] [/TR] [TR] [TD]Galaxy Weblinks--Video Playlist For YouTube [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube allows Stored XSS. This issue affects Video Playlist For YouTube: from n/a through 6.6.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32183&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32183]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32183')[/TD] [/TR] [TR] [TD]Galaxy Weblinks--WP Clone any post type [/TD] [TD]Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Clone any post type: from n/a through 3.4.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31872&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31872]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31872')[/TD] [/TR] [TR] [TD]Galaxy Weblinks--WP Clone any post type [/TD] [TD]URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type allows Phishing. This issue affects WP Clone any post type: from n/a through 3.4.[/TD] [TD]2025-04-01[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31871&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31871]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31871')[/TD] [/TR] [TR] [TD]GalleryCreator--Gallery Blocks with Lightbox [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32176&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32176]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32176')[/TD] [/TR] [TR] [TD]gb-plugins--GB Gallery Slideshow [/TD] [TD]Missing Authorization vulnerability in gb-plugins GB Gallery Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GB Gallery Slideshow: from n/a through 1.3.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31732&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31732]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31732')[/TD] [/TR] [TR] [TD]GhozyLab--Gallery Photo Albums Plugin [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery - Photo Albums Plugin allows Stored XSS. This issue affects Gallery - Photo Albums Plugin: from n/a through 1.3.170.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31586&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31586]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31586')[/TD] [/TR] [TR] [TD]gingerplugins--Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme allows Stored XSS. This issue affects Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme: from n/a through 1.1.[/TD] [TD]2025-03-31[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31610&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31610]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31610')[/TD] [/TR] [TR] [TD]GitoxideLabs--gitoxide [/TD] [TD]gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both of which implement standard SHA-1 without any mitigations for collision attacks. This means that two distinct Git objects with colliding SHA-1 hashes would break the Git object model and integrity checks when used with gitoxide. This vulnerability is fixed in 0.42.0.[/TD] [TD]2025-04-04[/TD] [TD][6.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31130&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N')[/TD] [TD][CVE-2025-31130]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31130')[/TD] [/TR] [TR] [TD]godcheese--Nimrod [/TD] [TD]A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is an unknown functionality of the file ViewMenuCategoryRestController.java. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3323&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3323]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3323')[/TD] [/TR] [TR] [TD]godcheese--Nimrod [/TD] [TD]A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file FileRestController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3324&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3324]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3324')[/TD] [/TR] [TR] [TD]Google--Chrome [/TD] [TD]Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)[/TD] [TD]2025-04-02[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3070&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N')[/TD] [TD][CVE-2025-3070]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3070')[/TD] [/TR] [TR] [TD]Gosign--Gosign Posts Slider Block [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gosign Gosign - Posts Slider Block allows Stored XSS. This issue affects Gosign - Posts Slider Block: from n/a through 1.1.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31891&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31891]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31891')[/TD] [/TR] [TR] [TD]Greg--TailPress [/TD] [TD]Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Greg TailPress allows Retrieve Embedded Sensitive Data. This issue affects TailPress: from n/a through 0.4.4.[/TD] [TD]2025-04-03[/TD] [TD][5.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31558&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31558]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31558')[/TD] [/TR] [TR] [TD]gunnarpayday--Payday [/TD] [TD]Missing Authorization vulnerability in gunnarpayday Payday allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Payday: from n/a through 3.3.12.[/TD] [TD]2025-04-03[/TD] [TD][5.8]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31876&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31876]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31876')[/TD] [/TR] [TR] [TD]GuoMinJim--PersonManage [/TD] [TD]A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the function preHandle of the file /login/. The manipulation of the argument Request leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3043&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-3043]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3043')[/TD] [/TR] [TR] [TD]HACHI--Crypt::Salt [/TD] [TD]Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.[/TD] [TD]2025-04-02[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1805&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L')[/TD] [TD][CVE-2025-1805]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1805')[/TD] [/TR] [TR] [TD]HCL Software--HCL DevOps Deploy / HCL Launch [/TD] [TD]HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.[/TD] [TD]2025-04-02[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0257&vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-0257]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0257')[/TD] [/TR] [TR] [TD]HCL Software--HCL DevOps Deploy / HCL Launch [/TD] [TD]HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.[/TD] [TD]2025-04-03[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0272&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-0272]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0272')[/TD] [/TR] [TR] [TD]HCL Software--HCL Traveler [/TD] [TD]HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests.[/TD] [TD]2025-04-03[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0278&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-0278]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0278')[/TD] [/TR] [TR] [TD]HCL Software--HCL Traveler [/TD] [TD]HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.[/TD] [TD]2025-04-03[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0279&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-0279]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0279')[/TD] [/TR] [TR] [TD]Hewlett Packard Enterprise (HPE)--HPE Athonet Core [/TD] [TD]An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer overflow.[/TD] [TD]2025-03-31[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-24456&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2024-24456]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24456')[/TD] [/TR] [TR] [TD]Hewlett Packard Enterprise (HPE)--Virtual Intranet Access (VIA) [/TD] [TD]A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients.[/TD] [TD]2025-04-01[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-25041&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-25041]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-25041')[/TD] [/TR] [TR] [TD]hiroprot--Terms Before Download [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hiroprot Terms Before Download allows Stored XSS. This issue affects Terms Before Download: from n/a through 1.0.4.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31614&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31614]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31614')[/TD] [/TR] [TR] [TD]Hossni Mubarak--JobWP [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP allows Cross Site Request Forgery. This issue affects JobWP: from n/a through 2.3.9.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32265&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32265]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32265')[/TD] [/TR] [TR] [TD]htplugins--Insert Headers and Footers Code HT Script [/TD] [TD]The Insert Headers and Footers Code - HT Script plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 1/true on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny access to legitimate users or be used to set some values to true, such as registration.[/TD] [TD]2025-04-02[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2779&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-2779]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2779')[/TD] [/TR] [TR] [TD]hutsixdigital--Tiger [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31407&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31407]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31407')[/TD] [/TR] [TR] [TD]IBM--Content Navigator [/TD] [TD]IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.[/TD] [TD]2025-04-02[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-56341&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2024-56341]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-56341')[/TD] [/TR] [TR] [TD]IBM--Jazz Reporting Service [/TD] [TD]IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.[/TD] [TD]2025-04-02[/TD] [TD][6.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-25051&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H')[/TD] [TD][CVE-2024-25051]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25051')[/TD] [/TR] [TR] [TD]IBM--Maximo Application Suite [/TD] [TD]IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.[/TD] [TD]2025-04-05[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1500&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-1500]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1500')[/TD] [/TR] [TR] [TD]IBM--TXSeries for Multiplatforms [/TD] [TD]IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.[/TD] [TD]2025-04-02[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-56475&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2024-56475]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-56475')[/TD] [/TR] [TR] [TD]IBM--TXSeries for Multiplatforms [/TD] [TD]IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.[/TD] [TD]2025-04-02[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-56476&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2024-56476]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-56476')[/TD] [/TR] [TR] [TD]IBM--TXSeries for Multiplatforms [/TD] [TD]IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.[/TD] [TD]2025-04-02[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-0154&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-0154]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-0154')[/TD] [/TR] [TR] [TD]IBM--TXSeries for Multiplatforms [/TD] [TD]IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.[/TD] [TD]2025-04-02[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2024-56474&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2024-56474]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-56474')[/TD] [/TR] [TR] [TD]icopydoc--Maps for WP [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP allows Stored XSS. This issue affects Maps for WP: from n/a through 1.2.4.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32179&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32179]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32179')[/TD] [/TR] [TR] [TD]ideaboxcreations--PowerPack Elementor Addons (Free Widgets, Extensions and Templates) [/TD] [TD]The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-01[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-1512&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-1512]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-1512')[/TD] [/TR] [TR] [TD]IDX Broker--IMPress for IDX Broker [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker allows Stored XSS. This issue affects IMPress for IDX Broker: from n/a through 3.2.3.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31556&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31556]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31556')[/TD] [/TR] [TR] [TD]ILLID--Advanced Woo Labels [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ILLID Advanced Woo Labels allows Stored XSS. This issue affects Advanced Woo Labels: from n/a through 2.14.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32188&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32188]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32188')[/TD] [/TR] [TR] [TD]Imtiaz Rayhan--Table Block by Tableberg [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imtiaz Rayhan Table Block by Tableberg allows Stored XSS. This issue affects Table Block by Tableberg: from n/a through 0.6.0.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32171&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32171]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32171')[/TD] [/TR] [TR] [TD]Inaba Denki Sangyo Co., Ltd.--CHOCO TEI WATCHER mini (IB-MCT001) [/TD] [TD]Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can access the microSD card used on the product may obtain the product login password.[/TD] [TD]2025-03-31[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-24852&vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N')[/TD] [TD][CVE-2025-24852]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-24852')[/TD] [/TR] [TR] [TD]InfoGiants--Simple Website Logo [/TD] [TD]Missing Authorization vulnerability in InfoGiants Simple Website Logo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Website Logo: from n/a through 1.1.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32258&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32258]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32258')[/TD] [/TR] [TR] [TD]Infoway LLC--Ebook Downloader [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infoway LLC Ebook Downloader allows Stored XSS. This issue affects Ebook Downloader: from n/a through 1.0.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31894&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31894]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31894')[/TD] [/TR] [TR] [TD]inspry--Agency Toolkit [/TD] [TD]Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Agency Toolkit: from n/a through 1.0.23.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31863&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31863]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31863')[/TD] [/TR] [TR] [TD]InternLM--LMDeploy [/TD] [TD]A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3162&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3162]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3162')[/TD] [/TR] [TR] [TD]InternLM--LMDeploy [/TD] [TD]A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3163&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3163]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3163')[/TD] [/TR] [TR] [TD]Iqonic Design--WPBookit [/TD] [TD]Missing Authorization vulnerability in Iqonic Design WPBookit allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WPBookit: from n/a through 1.0.1.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32254&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32254]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32254')[/TD] [/TR] [TR] [TD]istmoplugins--GetBookingsWP [/TD] [TD]Missing Authorization vulnerability in istmoplugins GetBookingsWP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GetBookingsWP: from n/a through 1.1.27.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31896&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-31896]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31896')[/TD] [/TR] [TR] [TD]IT Path Solutions--SCSS WP Editor [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor allows Cross Site Request Forgery. This issue affects SCSS WP Editor: from n/a through 1.1.8.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31808&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31808]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31808')[/TD] [/TR] [TR] [TD]iteaj--iboot [/TD] [TD]A vulnerability, which was classified as problematic, was found in iteaj iboot 物è”网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Password Handler. The manipulation of the argument ID leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-06[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3325&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-3325]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3325')[/TD] [/TR] [TR] [TD]itning--Student Homework Management System [/TD] [TD]A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.[/TD] [TD]2025-04-03[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3150&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-3150]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3150')[/TD] [/TR] [TR] [TD]itsourcecode--Library Management System [/TD] [TD]A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtuname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-04[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3245&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3245]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3245')[/TD] [/TR] [TR] [TD]J. Tyler Wiest--Jetpack Feedback Exporter [/TD] [TD]Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter allows Retrieve Embedded Sensitive Data. This issue affects Jetpack Feedback Exporter: from n/a through 1.23.[/TD] [TD]2025-04-04[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32251&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-32251]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32251')[/TD] [/TR] [TR] [TD]Jaap Jansma--Connector to CiviCRM with CiviMcRestFace [/TD] [TD]Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through 1.0.9.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31618&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31618]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31618')[/TD] [/TR] [TR] [TD]jackdewey--Link Library [/TD] [TD]The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-05[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2889&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-2889]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2889')[/TD] [/TR] [TR] [TD]Jacob Allred--Infusionsoft Web Form JavaScript [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacob Allred Infusionsoft Web Form JavaScript allows Stored XSS. This issue affects Infusionsoft Web Form JavaScript: from n/a through 1.1.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31629&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31629]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31629')[/TD] [/TR] [TR] [TD]jeffikus--WooTumblog [/TD] [TD]Missing Authorization vulnerability in jeffikus WooTumblog allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooTumblog: from n/a through 2.1.4.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31729&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31729]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31729')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins AsakusaSatellite Plugin [/TD] [TD]Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.[/TD] [TD]2025-04-02[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31727&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31727]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31727')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins AsakusaSatellite Plugin [/TD] [TD]Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.[/TD] [TD]2025-04-02[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31728&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31728]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31728')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins Cadence vManager Plugin [/TD] [TD]Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.[/TD] [TD]2025-04-02[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31724&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31724]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31724')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins monitor-remote-job Plugin [/TD] [TD]Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.[/TD] [TD]2025-04-02[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31725&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31725]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31725')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins Simple Queue Plugin [/TD] [TD]A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.[/TD] [TD]2025-04-02[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31723&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31723]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31723')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins Stack Hammer Plugin [/TD] [TD]Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.[/TD] [TD]2025-04-02[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31726&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31726]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31726')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins [/TD] [TD]A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.[/TD] [TD]2025-04-02[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31720&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31720]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31720')[/TD] [/TR] [TR] [TD]Jenkins Project--Jenkins [/TD] [TD]A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.[/TD] [TD]2025-04-02[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31721&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-31721]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31721')[/TD] [/TR] [TR] [TD]Jeroen Schmit--Theater for WordPress [/TD] [TD]Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Theater for WordPress: from n/a through 0.18.7.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31846&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31846]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31846')[/TD] [/TR] [TR] [TD]JFinal--CMS [/TD] [TD]A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. The manipulation of the argument template leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains that this is not a bug but a feature.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3214&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-3214]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3214')[/TD] [/TR] [TR] [TD]Jinher Network--OA [/TD] [TD]A vulnerability classified as critical was found in Jinher Network OA C6. Affected by this vulnerability is an unknown functionality of the file /C6/JHSoft.Web.NetDisk/NetDiskProperty.aspx. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3009&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3009]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3009')[/TD] [/TR] [TR] [TD]Joao Romao--Social Share Buttons & Analytics Plugin GetSocial.io [/TD] [TD]Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin - GetSocial.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Share Buttons & Analytics Plugin - GetSocial.io: from n/a through 4.5.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32239&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32239]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32239')[/TD] [/TR] [TR] [TD]John Housholder--Emma for WordPress [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in John Housholder Emma for WordPress allows Stored XSS. This issue affects Emma for WordPress: from n/a through 1.3.3.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32166&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32166]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32166')[/TD] [/TR] [TR] [TD]Jonathan Daggerhart--Query Wrangler [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler allows Cross Site Request Forgery. This issue affects Query Wrangler: from n/a through 1.5.53.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31779&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31779]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31779')[/TD] [/TR] [TR] [TD]JoomSky--JS Job Manager [/TD] [TD]Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31867&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31867]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31867')[/TD] [/TR] [TR] [TD]JoomSky--JS Job Manager [/TD] [TD]Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31868&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31868]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31868')[/TD] [/TR] [TR] [TD]joshix--Simplish [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joshix Simplish allows Stored XSS.This issue affects Simplish: from n/a through 2.6.4.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-22281&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-22281]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-22281')[/TD] [/TR] [TR] [TD]josselynj--pCloud Backup [/TD] [TD]Missing Authorization vulnerability in josselynj pCloud Backup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects pCloud Backup: from n/a through 1.0.1.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31755&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31755]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31755')[/TD] [/TR] [TR] [TD]jumpserver--jumpserver [/TD] [TD]JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes session feature and manipulate the kubeconfig file to redirect API requests to an external server controlled by the attacker. This allows the attacker to intercept and capture the Kubernetes cluster token. This can potentially allow unauthorized access to the cluster and compromise its security. This vulnerability is fixed in 4.8.0 and 3.10.18.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-27095&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-27095]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-27095')[/TD] [/TR] [TR] [TD]KaizenCoders--URL Shortify [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify allows Stored XSS. This issue affects URL Shortify: from n/a through 1.10.4.[/TD] [TD]2025-04-04[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32134&vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32134]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32134')[/TD] [/TR] [TR] [TD]Kenj_Frog --company-financial-management [/TD] [TD]A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management å…¬å¸è´¢åŠ¡ç®¡ç†ç³»ç»Ÿ 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.[/TD] [TD]2025-04-06[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3318&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3318]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3318')[/TD] [/TR] [TR] [TD]Kentico--Xperience [/TD] [TD]Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.[/TD] [TD]2025-04-06[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32369&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-32369]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32369')[/TD] [/TR] [TR] [TD]Kibru Demeke--Ethiopian Calendar [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kibru Demeke Ethiopian Calendar allows Stored XSS. This issue affects Ethiopian Calendar: from n/a through 1.1.1.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31589&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31589]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31589')[/TD] [/TR] [TR] [TD]KingAddons.com--King Addons for Elementor [/TD] [TD]Missing Authorization vulnerability in KingAddons.com King Addons for Elementor. This issue affects King Addons for Elementor: from n/a through 24.12.58.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30926&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-30926]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30926')[/TD] [/TR] [TR] [TD]Kishan--WP Link Preview [/TD] [TD]Server-Side Request Forgery (SSRF) vulnerability in Kishan WP Link Preview allows Server Side Request Forgery. This issue affects WP Link Preview: from n/a through 1.4.1.[/TD] [TD]2025-03-31[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31527&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-31527]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31527')[/TD] [/TR] [TR] [TD]Kuppuraj--Advanced All in One Admin Search by WP Spotlight [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight allows Cross Site Request Forgery. This issue affects Advanced All in One Admin Search by WP Spotlight: from n/a through 1.1.1.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32261&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-32261]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32261')[/TD] [/TR] [TR] [TD]LA-Studio--LA-Studio Element Kit for Elementor [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS. This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.4.9.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32194&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32194]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32194')[/TD] [/TR] [TR] [TD]LABCAT--Processing Projects [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LABCAT Processing Projects allows DOM-Based XSS. This issue affects Processing Projects: from n/a through 1.0.2.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31624&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31624]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31624')[/TD] [/TR] [TR] [TD]Labinator--Labinator Content Types Duplicator [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator allows Cross Site Request Forgery. This issue affects Labinator Content Types Duplicator: from n/a through 1.1.3.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31809&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31809]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31809')[/TD] [/TR] [TR] [TD]Leartes.NET--Leartes TRY Exchange Rates [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leartes.NET Leartes TRY Exchange Rates allows Stored XSS. This issue affects Leartes TRY Exchange Rates: from n/a through 2.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31783&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31783]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31783')[/TD] [/TR] [TR] [TD]Legrand--SMS PowerView [/TD] [TD]A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.[/TD] [TD]2025-03-31[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2982&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2982]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2982')[/TD] [/TR] [TR] [TD]Legrand--SMS PowerView [/TD] [TD]A vulnerability has been found in Legrand SMS PowerView 1.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument redirect leads to os command injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.[/TD] [TD]2025-03-31[/TD] [TD][5.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2983&vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2983]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2983')[/TD] [/TR] [TR] [TD]Magnigenie--RestroPress [/TD] [TD]Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RestroPress: from n/a through 3.1.8.4.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31877&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31877]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31877')[/TD] [/TR] [TR] [TD]Maksym Marko--MX Time Zone Clocks [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks allows Reflected XSS. This issue affects MX Time Zone Clocks: from n/a through 5.1.1.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31801&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31801]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31801')[/TD] [/TR] [TR] [TD]Manuel Schmalstieg--Minimalistic Event Manager [/TD] [TD]Missing Authorization vulnerability in Manuel Schmalstieg Minimalistic Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Minimalistic Event Manager: from n/a through 1.1.1.[/TD] [TD]2025-04-03[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31739&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31739]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31739')[/TD] [/TR] [TR] [TD]markkinchin--Beds24 Online Booking [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markkinchin Beds24 Online Booking allows Stored XSS. This issue affects Beds24 Online Booking: from n/a through 2.0.26.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31851&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31851]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31851')[/TD] [/TR] [TR] [TD]Mashi--Simple Map No Api [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api allows Stored XSS. This issue affects Simple Map No Api: from n/a through 1.9.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31890&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31890]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31890')[/TD] [/TR] [TR] [TD]Matat Technologies--TextMe SMS [/TD] [TD]Missing Authorization vulnerability in Matat Technologies TextMe SMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TextMe SMS: from n/a through 1.9.1.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31789&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N')[/TD] [TD][CVE-2025-31789]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31789')[/TD] [/TR] [TR] [TD]matthewrubin--Local Magic [/TD] [TD]Missing Authorization vulnerability in matthewrubin Local Magic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Local Magic: from n/a through 2.6.0.[/TD] [TD]2025-04-03[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31858&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31858]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31858')[/TD] [/TR] [TR] [TD]matthewrubin--Review Manager [/TD] [TD]Missing Authorization vulnerability in matthewrubin Review Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Manager: from n/a through 2.2.0.[/TD] [TD]2025-04-01[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31836&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31836]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31836')[/TD] [/TR] [TR] [TD]Mayeenul Islam--NanoSupport [/TD] [TD]Missing Authorization vulnerability in Mayeenul Islam NanoSupport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NanoSupport: from n/a through 0.6.0.[/TD] [TD]2025-03-31[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31376&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31376]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31376')[/TD] [/TR] [TR] [TD]metagauss--RegistrationMagic Custom Registration Forms, User Registration, Payment, and User Login [/TD] [TD]The RegistrationMagic - Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'payment_method' parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.[/TD] [TD]2025-04-04[/TD] [TD][6.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2836&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-2836]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2836')[/TD] [/TR] [TR] [TD]Microsoft--Microsoft Edge for iOS [/TD] [TD]Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.[/TD] [TD]2025-04-04[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-25001&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N')[/TD] [TD][CVE-2025-25001]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-25001')[/TD] [/TR] [TR] [TD]Microsoft--Microsoft Edge for iOS [/TD] [TD]User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.[/TD] [TD]2025-04-04[/TD] [TD][4.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29796&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N')[/TD] [TD][CVE-2025-29796]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29796')[/TD] [/TR] [TR] [TD]MiKa--OSM OpenStreetMap [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM - OpenStreetMap allows DOM-Based XSS. This issue affects OSM - OpenStreetMap: from n/a through 6.1.6.[/TD] [TD]2025-03-31[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31557&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31557]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31557')[/TD] [/TR] [TR] [TD]milan.latinovic--WP Chrono [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in milan.latinovic WP Chrono allows DOM-Based XSS. This issue affects WP Chrono: from n/a through 1.5.4.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31747&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31747]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31747')[/TD] [/TR] [TR] [TD]MobSF--Mobile-Security-Framework-MobSF [/TD] [TD]Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.[/TD] [TD]2025-03-31[/TD] [TD][4.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31116&vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L')[/TD] [TD][CVE-2025-31116]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31116')[/TD] [/TR] [TR] [TD]Modernaweb Studio--Black Widgets For Elementor [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS. This issue affects Black Widgets For Elementor: from n/a through 1.3.9.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31869&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-31869]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31869')[/TD] [/TR] [TR] [TD]MongoDB Inc--MongoDB Server [/TD] [TD]When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3084&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H')[/TD] [TD][CVE-2025-3084]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3084')[/TD] [/TR] [TR] [TD]Morgan Kay--Chamber Dashboard Business Directory [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.[/TD] [TD]2025-04-04[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-32162&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-32162]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-32162')[/TD] [/TR] [TR] [TD]moshensky--CF7 Spreadsheets [/TD] [TD]Missing Authorization vulnerability in moshensky CF7 Spreadsheets allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Spreadsheets: from n/a through 2.3.2.[/TD] [TD]2025-03-31[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31603&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-31603]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31603')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3028&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-3028]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3028')[/TD] [/TR] [TR] [TD]Mozilla--Firefox [/TD] [TD]An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3031&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N')[/TD] [TD][CVE-2025-3031]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3031')[/TD] [/TR] [TR] [TD]N-Media--Bulk Product Sync [/TD] [TD]Cross-Site Request Forgery (CSRF) vulnerability in N-Media Bulk Product Sync allows Cross Site Request Forgery. This issue affects Bulk Product Sync: from n/a through 8.6.[/TD] [TD]2025-04-01[/TD] [TD][4.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-31852&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N')[/TD] [TD][CVE-2025-31852]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-31852')[/TD] [/TR] [TR] [TD]N-Media--Nmedia MailChimp [/TD] [TD]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N-Media Nmedia MailChimp allows Stored XSS. This issue affects Nmedia MailChimp: from n/a through 5.4.[/TD] [TD]2025-04-01[/TD] [TD][6.5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-30613&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L')[/TD] [TD][CVE-2025-30613]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-30613')[/TD] [/TR] [TR] [TD]n/a--FastCMS [/TD] [TD]A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-04-03[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3177&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3177]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3177')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Directory Traversal vulnerability in ONLYOFFICE Document Server v.7.5.0 and before allows a remote attacker to obtain sensitive information via a crafted file upload.[/TD] [TD]2025-04-01[/TD] [TD][6.7]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2023-46988&vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N')[/TD] [TD][CVE-2023-46988]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46988')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.[/TD] [TD]2025-04-01[/TD] [TD][6.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29049&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-29049]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29049')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.[/TD] [TD]2025-04-02[/TD] [TD][6.1]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29719&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-29719]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29719')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.[/TD] [TD]2025-04-01[/TD] [TD][5.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2003-20001&vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2003-20001]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2003-20001')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.[/TD] [TD]2025-04-01[/TD] [TD][5.4]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-26054&vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N')[/TD] [TD][CVE-2025-26054]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-26054')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.[/TD] [TD]2025-04-01[/TD] [TD][5.9]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-29036&vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-29036]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-29036')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.[/TD] [TD]2025-04-01[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-28131&vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L')[/TD] [TD][CVE-2025-28131]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-28131')[/TD] [/TR] [TR] [TD]n/a--n/a [/TD] [TD]A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.[/TD] [TD]2025-04-01[/TD] [TD][4.6]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-28132&vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N')[/TD] [TD][CVE-2025-28132]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-28132')[/TD] [/TR] [TR] [TD]n/a--Projeqtor [/TD] [TD]A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tool/saveAttachment.php. The manipulation of the argument attachmentFiles leads to unrestricted upload. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 12.0.3 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains, that "this vulnerability can be exploited only on not securely installed instances, as it is adviced during product install: attachment directory should be out of web reach, so that even if executable file can be uploaded, it cannot be executed through the web."[/TD] [TD]2025-04-03[/TD] [TD][5]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3169&vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3169]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3169')[/TD] [/TR] [TR] [TD]n/a--PyTorch [/TD] [TD]A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2998&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2998]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2998')[/TD] [/TR] [TR] [TD]n/a--PyTorch [/TD] [TD]A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-2999&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-2999]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-2999')[/TD] [/TR] [TR] [TD]n/a--PyTorch [/TD] [TD]A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3000&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3000]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3000')[/TD] [/TR] [TR] [TD]n/a--PyTorch [/TD] [TD]A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.[/TD] [TD]2025-03-31[/TD] [TD][5.3]('https://nvd.nist.gov/cvss.cfm?version=2&name=CVE-2025-3001&vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L')[/TD] [TD][CVE-2025-3001]('https://nvd.nist.gov/nvd.cfm?cvename=CVE-2025-3001')[/TD] [/TR] [TR] [TD]n/a--react-draft-wysiwyg [/TD] [TD]All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the