Weekly Vulnerabilities Reports > February 10 to 16, 2025
Overview
351 new vulnerabilities reported during this period, including 35 critical vulnerabilities and 148 high severity vulnerabilities. This weekly summary report vulnerabilities in 152 products from 97 vendors including Microsoft, Adobe, Linux, PDF Xchange, and GNU. Vulnerabilities are notably categorized as "Cross-site Scripting", "SQL Injection", "Missing Authorization", "Out-of-bounds Write", and "Out-of-bounds Read".
- 265 reported vulnerabilities are remotely exploitables.
- 107 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 171 reported vulnerabilities are exploitable by an anonymous user.
- Microsoft has the most reported vulnerabilities, with 44 reported vulnerabilities.
- Dlink has the most reported critical vulnerabilities, with 3 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
35 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-02-14 | CVE-2024-13152 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0. | 10.0 | |
2025-02-16 | CVE-2025-1355 | Needyamin | Unrestricted Upload of File with Dangerous Type vulnerability in Needyamin Library Card System 1.0 A vulnerability was found in needyamin Library Card System 1.0. | 9.8 |
2025-02-15 | CVE-2024-12562 | S2Member | Deserialization of Untrusted Data vulnerability in S2Member The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. | 9.8 |
2025-02-15 | CVE-2024-13513 | Oliverpos | Missing Authorization vulnerability in Oliverpos Oliver POS The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. | 9.8 |
2025-02-13 | CVE-2025-24861 | Outbackpower | Command Injection vulnerability in Outbackpower Mojave Inverter Oghi8048A Firmware An attacker may inject commands via specially-crafted post requests. | 9.8 |
2025-02-13 | CVE-2025-24865 | Myscada | Missing Authentication for Critical Function vulnerability in Myscada Mypro The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | 9.8 |
2025-02-13 | CVE-2024-13182 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. | 9.8 | |
2025-02-13 | CVE-2024-13345 | Theme Fusion | Code Injection vulnerability in Theme-Fusion Avada The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. | 9.8 |
2025-02-13 | CVE-2024-13346 | Theme Fusion | Code Injection vulnerability in Theme-Fusion Avada The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. | 9.8 |
2025-02-13 | CVE-2024-10763 | Apuswp | Unspecified vulnerability in Apuswp Campress The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. | 9.8 |
2025-02-13 | CVE-2024-13770 | Themerex | Deserialization of Untrusted Data vulnerability in Themerex Puzzles The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. | 9.8 |
2025-02-12 | CVE-2024-57602 | Easyappointments | Unspecified vulnerability in Easyappointments 1.5.0 An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. | 9.8 |
2025-02-12 | CVE-2025-25343 | Tenda | Classic Buffer Overflow vulnerability in Tenda AC6 Firmware 15.03.05.16 Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function. | 9.8 |
2025-02-12 | CVE-2025-25742 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-853 Firmware 1.20B07 D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module. | 9.8 |
2025-02-12 | CVE-2025-25744 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-853 Firmware 1.20B07 D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module. | 9.8 |
2025-02-12 | CVE-2025-25746 | Dlink | Out-of-bounds Write vulnerability in Dlink Dir-853 Firmware 1.20B07 D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module. | 9.8 |
2025-02-12 | CVE-2025-0332 | Telerik | Path Traversal vulnerability in Telerik UI for Winforms In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | 9.8 |
2025-02-12 | CVE-2025-25349 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Daily Expense Tracker System 1.1 PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter. | 9.8 |
2025-02-12 | CVE-2025-25351 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Daily Expense Tracker System 1.1 PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter. | 9.8 |
2025-02-12 | CVE-2024-13477 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 2.5.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 9.8 |
2025-02-12 | CVE-2024-12213 | Apusthemes | Incorrect Privilege Assignment vulnerability in Apusthemes Superio The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. | 9.8 |
2025-02-12 | CVE-2025-1188 | Codezips | SQL Injection vulnerability in Codezips GYM Management System 1.0 A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. | 9.8 |
2025-02-12 | CVE-2025-1183 | Codezips | SQL Injection vulnerability in Codezips GYM Management System 1.0 A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. | 9.8 |
2025-02-12 | CVE-2025-26520 | Cacti | Unspecified vulnerability in Cacti 1.2.27/1.2.28 Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. | 9.8 |
2025-02-12 | CVE-2024-13421 | Contempothemes | Unspecified vulnerability in Contempothemes Real Estate 7 The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. | 9.8 |
2025-02-11 | CVE-2025-1044 | Logsign | Unspecified vulnerability in Logsign Unified Secops Platform Logsign Unified SecOps Platform Authentication Bypass Vulnerability. | 9.8 |
2025-02-11 | CVE-2024-52606 | Solarwinds | Server-Side Request Forgery (SSRF) vulnerability in Solarwinds Platform SolarWinds Platform is affected by server-side request forgery vulnerability. | 9.8 |
2025-02-11 | CVE-2025-0180 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. | 9.8 | |
2025-02-11 | CVE-2025-0181 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.7. | 9.8 | |
2025-02-11 | CVE-2025-1177 | Xunruicms | Deserialization of Untrusted Data vulnerability in Xunruicms 4.6.3 A vulnerability was found in dayrui XunRuiCMS 4.6.3. | 9.8 |
2025-02-11 | CVE-2025-1168 | Rems | Injection vulnerability in Rems Contact Manager With Export to VCF 1.0 A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. | 9.8 |
2025-02-10 | CVE-2025-1160 | Remyandrade | Unspecified vulnerability in Remyandrade Employee Management System 1.0 A vulnerability was found in SourceCodester Employee Management System 1.0. | 9.8 |
2025-02-10 | CVE-2024-13011 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. | 9.8 | |
2025-02-12 | CVE-2025-0108 | Paloaltonetworks | Missing Authentication for Critical Function vulnerability in Paloaltonetworks Pan-Os An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. | 9.1 |
2025-02-11 | CVE-2025-24409 | Adobe | Incorrect Authorization vulnerability in Adobe Commerce Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. | 9.1 |
148 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-02-16 | CVE-2025-1340 | Totolink | Stack-based Buffer Overflow vulnerability in Totolink X18 Firmware 9.1.0Cu.2024B20220329 A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. | 8.8 |
2025-02-16 | CVE-2025-1339 | Totolink | Command Injection vulnerability in Totolink X18 Firmware 9.1.0Cu.2024B20220329 A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. | 8.8 |
2025-02-12 | CVE-2025-1210 | Anisha | SQL Injection vulnerability in Anisha Wazifa System 1.0 A vulnerability classified as critical was found in code-projects Wazifa System 1.0. | 8.8 |
2025-02-12 | CVE-2024-11343 | Progress | Path Traversal vulnerability in Progress Telerik Document Processing Libraries In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | 8.8 |
2025-02-12 | CVE-2025-1206 | Codezips | SQL Injection vulnerability in Codezips GYM Management System 1.0 A vulnerability was found in Codezips Gym Management System 1.0. | 8.8 |
2025-02-12 | CVE-2024-10960 | Brizy | Unrestricted Upload of File with Dangerous Type vulnerability in Brizy The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. | 8.8 |
2025-02-12 | CVE-2025-1191 | Janobe | SQL Injection vulnerability in Janobe Multi Restaurant Table Reservation System 1.0 A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. | 8.8 |
2025-02-12 | CVE-2025-1192 | Janobe | SQL Injection vulnerability in Janobe Multi Restaurant Table Reservation System 1.0 A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. | 8.8 |
2025-02-12 | CVE-2024-12296 | Apusthemes | Missing Authorization vulnerability in Apusthemes Superio The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. | 8.8 |
2025-02-12 | CVE-2024-32838 | Apache | Unspecified vulnerability in Apache Fineract SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. | 8.8 |
2025-02-12 | CVE-2025-1189 | 1000Projects | SQL Injection vulnerability in 1000Projects Attendance Tracking Management System 1.0 A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. | 8.8 |
2025-02-12 | CVE-2024-13814 | Lcweb | Code Injection vulnerability in Lcweb Global Gallery The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. | 8.8 |
2025-02-12 | CVE-2024-13714 | The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_get_image_by_url' function in all versions up to, and including, 1.0.4. | 8.8 | |
2025-02-12 | CVE-2024-13653 | Mvpthemes | Missing Authorization vulnerability in Mvpthemes Zoxpress The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' function in all versions up to, and including, 2.12.0. | 8.8 |
2025-02-11 | CVE-2024-12547 | Tungstenautomation | Out-of-bounds Write vulnerability in Tungstenautomation Power PDF Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0899 | PDF Xchange | Use After Free vulnerability in Pdf-Xchange Editor PDF-XChange Editor AcroForm Use-After-Free Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0901 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0902 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0903 | PDF Xchange | Out-of-bounds Write vulnerability in Pdf-Xchange Editor PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0904 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0905 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0906 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0907 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0908 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0909 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0910 | PDF Xchange | Out-of-bounds Write vulnerability in Pdf-Xchange Editor PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-0911 | PDF Xchange | Out-of-bounds Read vulnerability in Pdf-Xchange Editor PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-1052 | Mintty Project | Out-of-bounds Write vulnerability in Mintty Project Mintty Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. | 8.8 |
2025-02-11 | CVE-2025-21190 | Microsoft | Unspecified vulnerability in Microsoft products Windows Telephony Service Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21200 | Microsoft | Unspecified vulnerability in Microsoft products Windows Telephony Service Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21201 | Microsoft | Unspecified vulnerability in Microsoft products Windows Telephony Server Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21208 | Microsoft | Unspecified vulnerability in Microsoft products Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21368 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Digest Authentication Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21369 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Digest Authentication Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21406 | Microsoft | Unspecified vulnerability in Microsoft products Windows Telephony Service Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21407 | Microsoft | Unspecified vulnerability in Microsoft products Windows Telephony Service Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-21410 | Microsoft | Unspecified vulnerability in Microsoft products Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 8.8 |
2025-02-11 | CVE-2025-24411 | Adobe | Unspecified vulnerability in Adobe Commerce Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 8.8 |
2025-02-11 | CVE-2025-24436 | Adobe | Unspecified vulnerability in Adobe Commerce and Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. | 8.8 |
2025-02-11 | CVE-2025-24437 | Adobe | Unspecified vulnerability in Adobe Commerce and Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. | 8.8 |
2025-02-11 | CVE-2025-22467 | Ivanti | Stack-based Buffer Overflow vulnerability in Ivanti Connect Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution. | 8.8 |
2025-02-11 | CVE-2024-45386 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4). | 8.8 | |
2025-02-11 | CVE-2024-13643 | The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. | 8.8 | |
2025-02-11 | CVE-2025-1172 | 1000Projects | SQL Injection vulnerability in 1000Projects Bookstore Management System 1.0 A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. | 8.8 |
2025-02-10 | CVE-2024-27859 | Apple | Unspecified vulnerability in Apple products The issue was addressed with improved memory handling. | 8.8 |
2025-02-14 | CVE-2024-12651 | Exposed Dangerous Method or Function vulnerability in PTT Inc. | 8.5 | |
2025-02-16 | CVE-2025-1336 | Cmseasy | Path Traversal vulnerability in Cmseasy 7.7.7.9 A vulnerability has been found in CmsEasy 7.7.7.9 and classified as problematic. | 8.1 |
2025-02-16 | CVE-2025-1335 | Cmseasy | Path Traversal vulnerability in Cmseasy 7.7.7.9 A vulnerability, which was classified as problematic, was found in CmsEasy 7.7.7.9. | 8.1 |
2025-02-12 | CVE-2025-26372 | Q Free | Missing Authorization vulnerability in Q-Free Maxtime A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users from groups via crafted HTTP requests. | 8.1 |
2025-02-12 | CVE-2024-13654 | Mvpthemes | Missing Authorization vulnerability in Mvpthemes Zoxpress The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. | 8.1 |
2025-02-12 | CVE-2024-13656 | Mvpthemes | Missing Authorization vulnerability in Mvpthemes Click MAG The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. | 8.1 |
2025-02-12 | CVE-2024-13800 | Convertplug | Missing Authorization vulnerability in Convertplug Convertplus The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. | 8.1 |
2025-02-11 | CVE-2025-21376 | Microsoft | Unspecified vulnerability in Microsoft products Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 8.1 |
2025-02-11 | CVE-2025-24407 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. | 8.1 |
2025-02-11 | CVE-2025-24418 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. | 8.1 |
2025-02-11 | CVE-2025-24422 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 8.1 |
2025-02-11 | CVE-2025-24423 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. | 8.1 |
2025-02-11 | CVE-2025-24424 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 8.1 |
2025-02-11 | CVE-2025-24426 | Adobe | Unspecified vulnerability in Adobe Commerce B2B Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 8.1 |
2025-02-11 | CVE-2025-24427 | Adobe | Unspecified vulnerability in Adobe Commerce Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. | 8.1 |
2025-02-11 | CVE-2025-24896 | Misskey | Insufficient Session Expiration vulnerability in Misskey Misskey is an open source, federated social media platform. | 8.1 |
2025-02-11 | CVE-2025-21400 | Microsoft | Unspecified vulnerability in Microsoft Sharepoint Server 16.0.17328.20362/2016/2019 Microsoft SharePoint Server Remote Code Execution Vulnerability | 8.0 |
2025-02-13 | CVE-2025-22480 | Dell | Link Following vulnerability in Dell Supportassist 3.2.0.90 Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. | 7.8 |
2025-02-12 | CVE-2024-12673 | An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system. This vulnerability only affects Vantage installed on these devices: * Lenovo V Series (Gen 5) * ThinkBook 14 (Gen 6, 7) * ThinkBook 16 (Gen 6, 7) * ThinkPad E Series (Gen 1) | 7.8 | |
2025-02-12 | CVE-2024-57951 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: hrtimers: Handle CPU state correctly on hotplug Consider a scenario where a CPU transitions from CPUHP_ONLINE to halfway through a CPU hotunplug down to CPUHP_HRTIMERS_PREPARE, and then back to CPUHP_ONLINE: Since hrtimers_prepare_cpu() does not run, cpu_base.hres_active remains set to 1 throughout. | 7.8 |
2025-02-12 | CVE-2025-1187 | Code Projects | Out-of-bounds Write vulnerability in Code-Projects Police FIR Record Management System 1.0 A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. | 7.8 |
2025-02-11 | CVE-2024-12549 | Tungstenautomation | Out-of-bounds Read vulnerability in Tungstenautomation Power PDF Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. | 7.8 |
2025-02-11 | CVE-2024-12550 | Tungstenautomation | Out-of-bounds Read vulnerability in Tungstenautomation Power PDF Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. | 7.8 |
2025-02-11 | CVE-2024-12551 | Tungstenautomation | Out-of-bounds Read vulnerability in Tungstenautomation Power PDF Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. | 7.8 |
2025-02-11 | CVE-2025-21156 | Adobe | Integer Underflow (Wrap or Wraparound) vulnerability in Adobe Incopy InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21159 | Adobe | Use After Free vulnerability in Adobe Illustrator 29.0/29.0.1/29.1 Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21160 | Adobe | Integer Underflow (Wrap or Wraparound) vulnerability in Adobe Illustrator 29.0/29.0.1/29.1 Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21161 | Adobe | Out-of-bounds Write vulnerability in Adobe Substance 3D Designer Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21163 | Adobe | Out-of-bounds Write vulnerability in Adobe Illustrator 29.0/29.0.1/29.1 Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21322 | Microsoft | Unspecified vulnerability in Microsoft PC Manager Microsoft PC Manager Elevation of Privilege Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21358 | Windows Core Messaging Elevation of Privileges Vulnerability | 7.8 | |
2025-02-11 | CVE-2025-21359 | Windows Kernel Security Feature Bypass Vulnerability | 7.8 | |
2025-02-11 | CVE-2025-21367 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 7.8 | |
2025-02-11 | CVE-2025-21373 | Microsoft | Unspecified vulnerability in Microsoft products Windows Installer Elevation of Privilege Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21375 | Microsoft | Unspecified vulnerability in Microsoft products Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21381 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Excel Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21386 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Excel Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21387 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Excel Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21390 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Excel Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21392 | Microsoft | Unspecified vulnerability in Microsoft 365 Apps and Office Microsoft Office Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21394 | Microsoft | Unspecified vulnerability in Microsoft products Microsoft Excel Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21397 | Microsoft | Unspecified vulnerability in Microsoft 365 Apps and Office Microsoft Office Remote Code Execution Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21418 | Microsoft | Unspecified vulnerability in Microsoft products Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21420 | Microsoft | Unspecified vulnerability in Microsoft products Windows Disk Cleanup Tool Elevation of Privilege Vulnerability | 7.8 |
2025-02-11 | CVE-2025-21121 | Adobe | Out-of-bounds Write vulnerability in Adobe Indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21123 | Adobe | Out-of-bounds Write vulnerability in Adobe Indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21157 | Adobe | Out-of-bounds Write vulnerability in Adobe Indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-11 | CVE-2025-21158 | Adobe | Integer Underflow (Wrap or Wraparound) vulnerability in Adobe Indesign InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2025-02-10 | CVE-2025-21687 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device. | 7.8 |
2025-02-10 | CVE-2025-21692 | Linux | Improper Validation of Array Index vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan <[email protected]> found that ets_class_from_arg() can index an Out-Of-Bound class in ets_class_from_arg() when passed clid of 0. | 7.8 |
2025-02-16 | CVE-2025-1356 | Needyamin | SQL Injection vulnerability in Needyamin Library Card System 1.0 A vulnerability was found in needyamin Library Card System 1.0. | 7.5 |
2025-02-15 | CVE-2024-13488 | Enituretechnology | SQL Injection vulnerability in Enituretechnology LTL Freight Quotes The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-14 | CVE-2024-13641 | Wpswings | Unspecified vulnerability in Wpswings Return Refund and Exchange for Woocommerce The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the 'attachment' directory. | 7.5 |
2025-02-13 | CVE-2025-22896 | Myscada | Cleartext Storage of Sensitive Information vulnerability in Myscada Mypro mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | 7.5 |
2025-02-13 | CVE-2025-25897 | TP Link | Out-of-bounds Write vulnerability in Tp-Link Tl-Wr841Nd Firmware A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. | 7.5 |
2025-02-13 | CVE-2025-25898 | TP Link | Out-of-bounds Write vulnerability in Tp-Link Tl-Wr841Nd Firmware A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm. | 7.5 |
2025-02-13 | CVE-2025-25901 | TP Link | Out-of-bounds Write vulnerability in Tp-Link Tl-Wr841Nd Firmware A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 parameters at /userRpm/WanSlaacCfgRpm.htm. | 7.5 |
2025-02-13 | CVE-2024-13606 | Wiselyhub | Unspecified vulnerability in Wiselyhub JS Help Desk The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. | 7.5 |
2025-02-12 | CVE-2024-56940 | Learndash | Unspecified vulnerability in Learndash 6.7.1 An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads. | 7.5 |
2025-02-12 | CVE-2025-1197 | Fabianros | SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0 A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. | 7.5 |
2025-02-12 | CVE-2024-13480 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13532 | Eniture | SQL Injection vulnerability in Eniture Small Package Quotes The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13435 | Infoway | SQL Injection vulnerability in Infoway Ebook Downloader The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13473 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameter in all versions up to, and including, 5.0.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13475 | Eniture | SQL Injection vulnerability in Eniture Small Package Quotes The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 4.5.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13490 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13528 | Wpfactory | Unspecified vulnerability in Wpfactory Customer Email Verification for Woocommerce The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. | 7.5 |
2025-02-12 | CVE-2024-13531 | Enituretechnology | SQL Injection vulnerability in Enituretechnology Shipengine Shipping Quotes The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-12 | CVE-2024-13600 | Majesticsupport | Unspecified vulnerability in Majesticsupport Majestic Support The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. | 7.5 |
2025-02-11 | CVE-2025-21351 | Windows Active Directory Domain Services API Denial of Service Vulnerability | 7.5 | |
2025-02-11 | CVE-2024-54089 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). | 7.5 | |
2025-02-11 | CVE-2025-24811 | A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0), SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0), SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0), SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-2XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-2XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-4XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-5XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-2XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0), SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0), SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0). | 7.5 | |
2025-02-11 | CVE-2025-1179 | GNU | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.43 A vulnerability was found in GNU Binutils 2.43. | 7.5 |
2025-02-11 | CVE-2025-21182 | Microsoft | Unspecified vulnerability in Microsoft Windows 11 24H2 and Windows Server 2025 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 7.4 |
2025-02-11 | CVE-2025-21183 | Microsoft | Unspecified vulnerability in Microsoft Windows 11 24H2 and Windows Server 2025 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | 7.4 |
2025-02-16 | CVE-2025-1338 | A vulnerability was found in NUUO Camera up to 20250203. | 7.3 | |
2025-02-11 | CVE-2025-21206 | Microsoft | Unspecified vulnerability in Microsoft Visual Studio 2019 and Visual Studio 2022 Visual Studio Installer Elevation of Privilege Vulnerability | 7.3 |
2025-02-11 | CVE-2025-24039 | Visual Studio Code Elevation of Privilege Vulnerability | 7.3 | |
2025-02-11 | CVE-2025-24042 | Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 7.3 | |
2025-02-10 | CVE-2025-1156 | A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. | 7.3 | |
2025-02-14 | CVE-2024-55904 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements. | 7.2 | |
2025-02-13 | CVE-2025-25352 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Land Record System 1.0 A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter. | 7.2 |
2025-02-13 | CVE-2025-25354 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Land Record System 1.0 A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter. | 7.2 |
2025-02-13 | CVE-2025-25355 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Land Record System 1.0 A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter. | 7.2 |
2025-02-13 | CVE-2025-25356 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Land Record System 1.0 A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the " todate" POST request parameter. | 7.2 |
2025-02-13 | CVE-2025-25357 | Phpgurukul | SQL Injection vulnerability in PHPgurukul Land Record System 1.0 A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the email POST request parameter. | 7.2 |
2025-02-12 | CVE-2024-11628 | Telerik | Unspecified vulnerability in Telerik Kendo UI for VUE In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | 7.2 |
2025-02-12 | CVE-2025-25743 | Dlink | Command Injection vulnerability in Dlink Dir-853 Firmware 1.20B07 D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module. | 7.2 |
2025-02-12 | CVE-2024-12629 | Telerik | Unspecified vulnerability in Telerik Kendoreact In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | 7.2 |
2025-02-11 | CVE-2024-47908 | Ivanti | OS Command Injection vulnerability in Ivanti Cloud Services Appliance OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | 7.2 |
2025-02-11 | CVE-2025-24499 | A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). | 7.2 | |
2025-02-11 | CVE-2025-1173 | 1000Projects | SQL Injection vulnerability in 1000Projects Bookstore Management System 1.0 A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. | 7.2 |
2025-02-11 | CVE-2025-21194 | Microsoft Surface Security Feature Bypass Vulnerability | 7.1 | |
2025-02-11 | CVE-2025-21379 | Microsoft | Unspecified vulnerability in Microsoft Windows 11 24H2 and Windows Server 2025 DHCP Client Service Remote Code Execution Vulnerability | 7.1 |
2025-02-11 | CVE-2025-21391 | Microsoft | Unspecified vulnerability in Microsoft products Windows Storage Elevation of Privilege Vulnerability | 7.1 |
2025-02-11 | CVE-2025-21419 | Microsoft | Unspecified vulnerability in Microsoft products Windows Setup Files Cleanup Elevation of Privilege Vulnerability | 7.1 |
2025-02-11 | CVE-2024-13813 | Ivanti | Incorrect Permission Assignment for Critical Resource vulnerability in Ivanti Secure Access Client Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. | 7.1 |
2025-02-11 | CVE-2025-24807 | Eprosima | Insufficient Verification of Data Authenticity vulnerability in Eprosima Fast DDS eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). | 7.1 |
2025-02-11 | CVE-2025-24868 | The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. | 7.1 | |
2025-02-11 | CVE-2025-21184 | Microsoft | Unspecified vulnerability in Microsoft products Windows Core Messaging Elevation of Privileges Vulnerability | 7.0 |
2025-02-11 | CVE-2025-21414 | Microsoft | Unspecified vulnerability in Microsoft products Windows Core Messaging Elevation of Privileges Vulnerability | 7.0 |
2025-02-11 | CVE-2025-24036 | Microsoft | Unspecified vulnerability in Microsoft Autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | 7.0 |
2025-02-11 | CVE-2025-23403 | A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). | 7.0 |