Weekly Vulnerabilities Reports > March 3 to 9, 2025

Overview

378 new vulnerabilities reported during this period, including 54 critical vulnerabilities and 116 high severity vulnerabilities. This weekly summary report vulnerabilities in 534 products from 98 vendors including Openatom, Qualcomm, Linux, Phpgurukul, and Huawei. Vulnerabilities are notably categorized as "Cross-site Scripting", "Injection", "SQL Injection", "Missing Authorization", and "NULL Pointer Dereference".

  • 275 reported vulnerabilities are remotely exploitables.
  • 104 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 166 reported vulnerabilities are exploitable by an anonymous user.
  • Openatom has the most reported vulnerabilities, with 26 reported vulnerabilities.
  • Phpgurukul has the most reported critical vulnerabilities, with 9 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

54 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-08 CVE-2024-13359 Tychesoftwares Unrestricted Upload of File with Dangerous Type vulnerability in Tychesoftwares Product Input Fields for Woocommerce

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0.

9.8
2025-03-08 CVE-2025-1323 Plechevandrey SQL Injection vulnerability in Plechevandrey Wp-Recall

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

9.8
2025-03-08 CVE-2025-0177 Javothemes Improper Privilege Management vulnerability in Javothemes Javo Core

The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080.

9.8
2025-03-08 CVE-2024-11087 Miniorange Improper Authentication vulnerability in Miniorange Social Login

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9.

9.8
2025-03-07 CVE-2025-2097 Totolink Out-of-bounds Write vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.

9.8
2025-03-07 CVE-2025-2094 Totolink OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316

A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.

9.8
2025-03-07 CVE-2025-2095 Totolink OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316

A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.

9.8
2025-03-07 CVE-2025-2096 Totolink OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316

A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.

9.8
2025-03-07 CVE-2025-2088 Phpgurukul Injection vulnerability in PHPgurukul Pre-School Enrollment System 1.0

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0.

9.8
2025-03-07 CVE-2024-12876 Uxper Missing Authorization vulnerability in Uxper Golo

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10.

9.8
2025-03-07 CVE-2025-1315 Sfwebservice Authentication Bypass Using an Alternate Path or Channel vulnerability in Sfwebservice Injob

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1.

9.8
2025-03-07 CVE-2025-1475 The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5.
9.8
2025-03-06 CVE-2024-12144 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection.This issue affects Finder ERP/CRM (Old System): before 18.12.2024.
9.8
2025-03-05 CVE-2024-12097 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informatics E-Travel allows SQL Injection.This issue affects E-Travel: before 15.12.2024.
9.8
2025-03-05 CVE-2024-13147 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection.This issue affects B2B Login Panel: before 15.01.2025.
9.8
2025-03-05 CVE-2024-11951 The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0.
9.8
2025-03-05 CVE-2024-12281 The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2.
9.8
2025-03-05 CVE-2024-13787 The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function.
9.8
2025-03-05 CVE-2025-1515 The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8.
9.8
2025-03-05 CVE-2025-1393 An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.
9.8
2025-03-05 CVE-2025-1966 Phpgurukul Unspecified vulnerability in PHPgurukul Pre-School Enrollment System 1.0

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0.

9.8
2025-03-05 CVE-2025-1965 Projectworlds SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0

A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0.

9.8
2025-03-05 CVE-2025-1316 Edimax OS Command Injection vulnerability in Edimax Ic-7100 Firmware

Edimax IC-7100 does not properly neutralize requests.

9.8
2025-03-05 CVE-2025-1962 Projectworlds SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0

A vulnerability was found in projectworlds Online Hotel Booking 1.0.

9.8
2025-03-05 CVE-2025-1963 Projectworlds SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0

A vulnerability was found in projectworlds Online Hotel Booking 1.0.

9.8
2025-03-04 CVE-2025-1959 Codezips Unspecified vulnerability in Codezips GYM Management System 1.0

A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0.

9.8
2025-03-04 CVE-2025-1956 Code Projects Injection vulnerability in Code-Projects Shopping Portal 1.0

A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0.

9.8
2025-03-04 CVE-2025-1952 Phpgurukul Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0

A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0.

9.8
2025-03-04 CVE-2025-1307 Spicethemes Missing Authorization vulnerability in Spicethemes Newscrunch

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1.

9.8
2025-03-04 CVE-2025-1906 Phpgurukul Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0

A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical.

9.8
2025-03-04 CVE-2025-0912 Givewp Deserialization of Untrusted Data vulnerability in Givewp

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter.

9.8
2025-03-04 CVE-2025-1900 Phpgurukul Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical.

9.8
2025-03-04 CVE-2025-1901 Phpgurukul Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0.

9.8
2025-03-04 CVE-2025-1902 Phpgurukul Unspecified vulnerability in PHPgurukul Student Record System 3.2

A vulnerability was found in PHPGurukul Student Record System 3.2.

9.8
2025-03-04 CVE-2025-1903 Codezips Unspecified vulnerability in Codezips Online Shopping Website 1.0

A vulnerability was found in Codezips Online Shopping Website 1.0.

9.8
2025-03-04 CVE-2025-1894 Phpgurukul Injection vulnerability in PHPgurukul Restaurant Table Booking System 1.0

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0.

9.8
2025-03-04 CVE-2025-1890 Shishuocms Project Unrestricted Upload of File with Dangerous Type vulnerability in Shishuocms Project Shishuocms 1.1

A vulnerability has been found in shishuocms 1.1 and classified as critical.

9.8
2025-03-03 CVE-2025-1889 Mmaitre314 Unspecified vulnerability in Mmaitre314 Picklescan

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan.

9.8
2025-03-03 CVE-2025-26970 Arktheme Code Injection vulnerability in Arktheme the ARK

Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Ark Theme Core allows Code Injection.

9.8
2025-03-03 CVE-2025-1869 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.

9.8
2025-03-03 CVE-2025-1870 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.

9.8
2025-03-03 CVE-2025-1871 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.

9.8
2025-03-03 CVE-2025-1872 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.

9.8
2025-03-03 CVE-2025-1873 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.

9.8
2025-03-03 CVE-2025-1874 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.

9.8
2025-03-03 CVE-2025-1875 Mayurik SQL Injection vulnerability in Mayurik Best Online News Portal 1.0

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.

9.8
2025-03-03 CVE-2025-1859 Phpgurukul Injection vulnerability in PHPgurukul News Portal 4.1

A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1.

9.8
2025-03-03 CVE-2025-1852 Totolink Classic Buffer Overflow vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical.

9.8
2025-03-03 CVE-2025-1853 Tenda Stack-based Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical.

9.8
2025-03-03 CVE-2025-1850 Codezips Unspecified vulnerability in Codezips College Management System 1.0

A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0.

9.8
2025-03-03 CVE-2025-27590 Oxidized WEB Project Unspecified vulnerability in Oxidized web Project Oxidized web

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

9.8
2025-03-03 CVE-2024-51962 Esri SQL Injection vulnerability in Esri Arcgis Server 10.9.1/11.1

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.

9.6
2025-03-08 CVE-2024-13924 Fancywp Server-Side Request Forgery (SSRF) vulnerability in Fancywp Starter Templates

The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter.

9.1
2025-03-07 CVE-2024-13904 Platformly Server-Side Request Forgery (SSRF) vulnerability in Platformly Platform.Ly for Woocommerce

The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function.

9.1

116 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-09 CVE-2025-2126 Joomlaux Injection vulnerability in Joomlaux JUX Real Estate 3.4.0

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical.

8.8
2025-03-08 CVE-2024-11640 E4Jconnect Cross-Site Request Forgery (CSRF) vulnerability in E4Jconnect Vikrentcar

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2.

8.8
2025-03-08 CVE-2024-13882 Coderevolution Unrestricted Upload of File with Dangerous Type vulnerability in Coderevolution Aiomatic

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_generate_featured_image' function in all versions up to, and including, 2.3.8.

8.8
2025-03-07 CVE-2024-12035 The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including, 6.9.
8.8
2025-03-07 CVE-2024-9658 Dasinfomedia Authentication Bypass Using an Alternate Path or Channel vulnerability in Dasinfomedia School Management System

The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0.

8.8
2025-03-07 CVE-2025-1309 The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() function in all versions up to, and including, 3.5.04.
8.8
2025-03-05 CVE-2024-13232 The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitrary SQL Execution and privilege escalation due to a missing capability check on the renderImport() function in all versions up to, and including, 4.1.1.
8.8
2025-03-04 CVE-2025-1306 Spicethemes Cross-Site Request Forgery (CSRF) vulnerability in Spicethemes Newscrunch

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4.

8.8
2025-03-04 CVE-2025-1321 Mtrv SQL Injection vulnerability in Mtrv Teachpress

The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

8.8
2025-03-04 CVE-2025-1639 Crowdytheme Missing Authorization vulnerability in Crowdytheme Arolax

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6.

8.8
2025-03-04 CVE-2025-1891 Qzw1210 Cross-Site Request Forgery (CSRF) vulnerability in Qzw1210 Shishuocms 1.1

A vulnerability was found in shishuocms 1.1 and classified as problematic.

8.8
2025-03-03 CVE-2025-25967 Ddsn Unspecified vulnerability in Ddsn Acora CMS 10.1.1

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF).

8.8
2025-03-03 CVE-2025-26967 Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory allows Object Injection.
8.8
2025-03-03 CVE-2024-53029 Qualcomm Improper Input Validation vulnerability in Qualcomm products

Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

8.8
2025-03-03 CVE-2025-24654 Squirrly Missing Authorization vulnerability in Squirrly SEO Plugin BY Squirrly SEO

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.4.05.

8.8
2025-03-04 CVE-2024-9149 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection.This issue affects E-Commerce Website Template: before v1.5.
8.6
2025-03-04 CVE-2024-48248 Nakivo Unspecified vulnerability in Nakivo Backup & Replication Director 9.4.0.R43656

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

8.6
2025-03-04 CVE-2025-22224 Vmware Unspecified vulnerability in VMWare products

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

8.2
2025-03-07 CVE-2024-13655 The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.5.2.
8.1
2025-03-07 CVE-2025-0749 The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3.
8.1
2025-03-05 CVE-2024-13777 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter.
8.1
2025-03-05 CVE-2025-0956 The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.3.0 via deserialization of untrusted input from the 'raccookie_guest_email' cookie.
8.1
2025-03-04 CVE-2025-23368 A flaw was found in Wildfly Elytron integration.
8.1
2025-03-03 CVE-2025-1801 A flaw was found in the Ansible aap-gateway.
8.1
2025-03-06 CVE-2024-58055 Linux Double Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Don't free command immediately Don't prematurely free the command.

7.8
2025-03-06 CVE-2024-58069 Linux Out-of-bounds Write vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read The nvmem interface supports variable buffer sizes, while the regmap interface operates with fixed-size storage.

7.8
2025-03-04 CVE-2020-23438 Wondershare Uncontrolled Search Path Element vulnerability in Wondershare Filmora 9.2.11

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

7.8
2025-03-04 CVE-2025-0587 Openatom Integer Overflow or Wraparound vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

7.8
2025-03-04 CVE-2025-20091 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2025-03-04 CVE-2025-20626 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2025-03-04 CVE-2025-21084 Openatom NULL Pointer Dereference vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference..

7.8
2025-03-04 CVE-2025-22835 Openatom Out-of-bounds Write vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

7.8
2025-03-04 CVE-2025-23240 Openatom Out-of-bounds Write vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

7.8
2025-03-04 CVE-2025-23409 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2025-03-04 CVE-2025-23414 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2025-03-04 CVE-2025-23420 Openatom Out-of-bounds Write vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

7.8
2025-03-04 CVE-2025-24301 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2025-03-04 CVE-2025-24309 Openatom Out-of-bounds Write vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

7.8
2025-03-03 CVE-2024-45782 GNU
Redhat
A flaw was found in the HFS filesystem.
7.8
2025-03-03 CVE-2025-0678 GNU
Redhat
A flaw was found in grub2.
7.8
2025-03-03 CVE-2024-43055 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Memory corruption while processing camera use case IOCTL call.

7.8
2025-03-03 CVE-2024-43057 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption while processing command in Glink linux.

7.8
2025-03-03 CVE-2024-43059 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

7.8
2025-03-03 CVE-2024-43060 Qualcomm Use of Out-of-range Pointer Offset vulnerability in Qualcomm products

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

7.8
2025-03-03 CVE-2024-43061 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.

7.8
2025-03-03 CVE-2024-43062 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.

7.8
2025-03-03 CVE-2024-45580 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.

7.8
2025-03-03 CVE-2024-49836 Qualcomm Improper Validation of Array Index vulnerability in Qualcomm products

Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.

7.8
2025-03-03 CVE-2024-53012 Qualcomm Improper Input Validation vulnerability in Qualcomm products

Memory corruption may occur due to improper input validation in clock device.

7.8
2025-03-03 CVE-2024-53014 Qualcomm Improper Validation of Array Index vulnerability in Qualcomm products

Memory corruption may occur while validating ports and channels in Audio driver.

7.8
2025-03-03 CVE-2024-53022 Qualcomm Improper Input Validation vulnerability in Qualcomm products

Memory corruption may occur during communication between primary and guest VM.

7.8
2025-03-03 CVE-2024-53023 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption may occur while accessing a variable during extended back to back tests.

7.8
2025-03-03 CVE-2024-53024 Qualcomm NULL Pointer Dereference vulnerability in Qualcomm products

Memory corruption in display driver while detaching a device.

7.8
2025-03-03 CVE-2024-53030 Qualcomm Improper Input Validation vulnerability in Qualcomm products

Memory corruption while processing input message passed from FE driver.

7.8
2025-03-03 CVE-2024-53031 Qualcomm Improper Input Validation vulnerability in Qualcomm products

Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

7.8
2025-03-03 CVE-2024-53033 Qualcomm Untrusted Pointer Dereference vulnerability in Qualcomm products

Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.

7.8
2025-03-03 CVE-2024-53034 Qualcomm Untrusted Pointer Dereference vulnerability in Qualcomm products

Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.

7.8
2025-03-03 CVE-2025-21424 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption while calling the NPU driver APIs concurrently.

7.8
2025-03-06 CVE-2024-7872 Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data.This issue affects Extreme XDS: before 3933.
7.6
2025-03-05 CVE-2024-11216 Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: through 05.03.2025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
7.6
2025-03-07 CVE-2025-27604 Xwiki Information Exposure vulnerability in Xwiki Confluence Migrator

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance.

7.5
2025-03-07 CVE-2024-10804 The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file.
7.5
2025-03-07 CVE-2024-12036 The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function.
7.5
2025-03-07 CVE-2024-13320 The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-03-06 CVE-2025-27598 Sixlabors Unspecified vulnerability in Sixlabors Imagesharp

ImageSharp is a 2D graphics API.

7.5
2025-03-06 CVE-2024-51476 IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
7.5
2025-03-06 CVE-2024-12146 Improper Validation of Syntactic Correctness of Input vulnerability in Finder Fire Safety Finder ERP/CRM (New System) allows SQL Injection.This issue affects Finder ERP/CRM (New System): before 18.12.2024.
7.5
2025-03-05 CVE-2024-13471 The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7.
7.5
2025-03-05 CVE-2025-1702 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 2.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-03-04 CVE-2025-1899 Tenda Classic Buffer Overflow vulnerability in Tenda TX3 Firmware 16.03.13.11

A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical.

7.5
2025-03-04 CVE-2025-1895 Tenda Classic Buffer Overflow vulnerability in Tenda TX3 Firmware 16.03.13.11

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi.

7.5
2025-03-04 CVE-2025-1896 Tenda Classic Buffer Overflow vulnerability in Tenda TX3 Firmware 16.03.13.11

A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi.

7.5
2025-03-04 CVE-2025-1897 Tenda Classic Buffer Overflow vulnerability in Tenda TX3 Firmware 16.03.13.11

A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi.

7.5
2025-03-04 CVE-2025-1898 Tenda Classic Buffer Overflow vulnerability in Tenda TX3 Firmware 16.03.13.11

A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi.

7.5
2025-03-04 CVE-2025-1893 Open5Gs Unspecified vulnerability in Open5Gs

A vulnerability was found in Open5GS up to 2.7.2.

7.5
2025-03-04 CVE-2025-27219 Ruby Lang Unspecified vulnerability in Ruby-Lang CGI

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability.

7.5
2025-03-04 CVE-2025-27220 Ruby Lang Unspecified vulnerability in Ruby-Lang CGI

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

7.5
2025-03-03 CVE-2024-51961 Esri External Control of File Name or Path vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files from the remote server.  Due to the nature of the files accessible in this vulnerability the impact to confidentiality is High there is no impact to both integrity or availability.

7.5
2025-03-03 CVE-2025-1877 Dlink Improper Resource Shutdown or Release vulnerability in Dlink Dap-1562 Firmware 1.10

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10.

7.5
2025-03-03 CVE-2025-25301 Danielgatis Server-Side Request Forgery (SSRF) vulnerability in Danielgatis Rembg

Rembg is a tool to remove images background.

7.5
2025-03-03 CVE-2024-41770 IBM Insufficiently Protected Credentials vulnerability in IBM Engineering Requirements Management Doors Next 7.0.2/7.0.3/7.1

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

7.5
2025-03-03 CVE-2024-41771 IBM Insufficiently Protected Credentials vulnerability in IBM Engineering Requirements Management Doors Next 7.0.2/7.0.3/7.1

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

7.5
2025-03-03 CVE-2025-25185 Binary Husky Link Following vulnerability in Binary-Husky GPT Academic

GPT Academic provides interactive interfaces for large language models.

7.5
2025-03-03 CVE-2025-27419 Wegia Allocation of Resources Without Limits or Throttling vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

7.5
2025-03-03 CVE-2025-26988 Cozyvision SQL Injection vulnerability in Cozyvision SMS Alert Order Notifications

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection.

7.5
2025-03-03 CVE-2024-53027 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Transient DOS may occur while processing the country IE.

7.5
2025-03-09 CVE-2025-2118 A vulnerability was found in Quantico Tecnologia PRMV 6.48.
7.3
2025-03-07 CVE-2025-2066 A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical.
7.3
2025-03-07 CVE-2025-2067 A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical.
7.3
2025-03-07 CVE-2025-2062 A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0.
7.3
2025-03-07 CVE-2025-2063 A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0.
7.3
2025-03-07 CVE-2025-2064 A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0.
7.3
2025-03-07 CVE-2025-2065 A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0.
7.3
2025-03-07 CVE-2025-2060 A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0.
7.3
2025-03-07 CVE-2025-2057 A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0.
7.3
2025-03-07 CVE-2025-2058 A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical.
7.3
2025-03-07 CVE-2025-2059 A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical.
7.3
2025-03-07 CVE-2025-2050 A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3.
7.3
2025-03-06 CVE-2025-2038 A vulnerability was found in code-projects Blood Bank Management System 1.0.
7.3
2025-03-06 CVE-2025-2030 A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform up to 20250224.
7.3
2025-03-05 CVE-2025-1964 A vulnerability was found in projectworlds Online Hotel Booking 1.0.
7.3
2025-03-04 CVE-2025-1954 A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
7.3
2025-03-03 CVE-2025-1858 A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0.
7.3
2025-03-03 CVE-2025-1856 A vulnerability was found in Codezips Gym Management System 1.0.
7.3
2025-03-03 CVE-2025-1857 A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0.
7.3
2025-03-09 CVE-2025-2132 Ftcms Injection vulnerability in Ftcms 2.1

A vulnerability classified as critical has been found in ftcms 2.1.

7.2
2025-03-08 CVE-2024-13908 Bestwebsoft Unrestricted Upload of File with Dangerous Type vulnerability in Bestwebsoft Smtp

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 1.1.9.

7.2
2025-03-08 CVE-2024-13835 Wpexpertplugins Improper Privilege Management vulnerability in Wpexpertplugins Post Meta Data Manager

The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.3.

7.2
2025-03-08 CVE-2024-13890 Sksdev Code Injection vulnerability in Sksdev Allow PHP Execute 1.0

The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.

7.2
2025-03-07 CVE-2024-13906 The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function.
7.2
2025-03-07 CVE-2025-0162 IBM XXE vulnerability in IBM Aspera Shares 1.10.0/1.9.14/1.9.15

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.

7.1
2025-03-05 CVE-2025-20206 A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco Secure Client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time.
7.1
2025-03-03 CVE-2024-51954 Esri Improper Access Control vulnerability in Esri Arcgis Server 10.9.1/11.1

There is an improper access control issue in ArcGIS Server versions 10.9.1 through 11.3 on Windows and Linux, which under unique circumstances, could potentially allow a remote, low privileged authenticated attacker to access secure services published a standalone (Unfederated) ArcGIS Server instance.  If successful this compromise would have a high impact on Confidentiality, low impact on integrity and no impact to availability of the software.

7.1
2025-03-03 CVE-2025-1882 I Drive Register Interface Allows Software Access to Sensitive Data or Security Settings vulnerability in I-Drive I11 Firmware and I12 Firmware

A vulnerability was found in i-Drive i11 and i12 up to 20250227.

7.0
2025-03-03 CVE-2024-53028 Qualcomm Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products

Memory corruption may occur while processing message from frontend during allocation.

7.0
2025-03-03 CVE-2024-53032 Qualcomm Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products

Memory corruption may occur in keyboard virtual device due to guest VM interaction.

7.0

200 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-08 CVE-2025-27840 Espressif Unspecified vulnerability in Espressif Esp32 Firmware

Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).

6.8
2025-03-03 CVE-2025-1879 I Drive Use of Hard-coded Password vulnerability in I-Drive I11 Firmware and I12 Firmware

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic.

6.8
2025-03-03 CVE-2024-45780 GNU Unspecified vulnerability in GNU Grub2

A flaw was found in grub2.

6.7
2025-03-08 CVE-2024-13774 Wpfactory Cross-Site Request Forgery (CSRF) vulnerability in Wpfactory Wishlist for Woocommerce

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7.

6.5
2025-03-08 CVE-2025-1504 Andypalmer Missing Authorization vulnerability in Andypalmer Post Lockdown

The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due to insufficient restrictions on which posts can be included.

6.5
2025-03-07 CVE-2025-1768 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to, and including, 12.4.05 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-03-07 CVE-2024-12607 The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-03-07 CVE-2024-12609 The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the mj_smgt_view_student_attendance() function.
6.5
2025-03-07 CVE-2024-13781 Heroplugins SQL Injection vulnerability in Heroplugins Hero Maps Premium

The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-03-07 CVE-2025-0959 Imithemes SQL Injection: Hibernate vulnerability in Imithemes Eventer

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-03-06 CVE-2024-13897 The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_page function in all versions up to, and including, 1.22.
6.5
2025-03-05 CVE-2024-13778 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several functions in all versions up to, and including, 1.16.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-03-05 CVE-2024-13780 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5.
6.5
2025-03-05 CVE-2024-13809 The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-03-05 CVE-2024-13815 The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7.
6.5
2025-03-05 CVE-2025-0954 The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in all versions up to, and including, 5.1.4.
6.5
2025-03-03 CVE-2025-25302 Danielgatis Origin Validation Error vulnerability in Danielgatis Rembg

Rembg is a tool to remove images background.

6.5
2025-03-03 CVE-2024-43169 IBM Download of Code Without Integrity Check vulnerability in IBM Engineering Requirements Management Doors Next 7.0.2/7.0.3/7.1

IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code.

6.5
2025-03-03 CVE-2024-43056 Qualcomm Buffer Over-read vulnerability in Qualcomm products

Transient DOS during hypervisor virtual I/O operation in a virtual machine.

6.5
2025-03-08 CVE-2024-12460 The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-07 CVE-2024-13805 The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping.
6.4
2025-03-07 CVE-2025-0863 The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-07 CVE-2024-12809 The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-11731 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-12815 The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortcode in all versions up to, and including, 0.1.6 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-13757 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-5667 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-13350 The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-03-05 CVE-2024-13866 The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping.
6.4
2025-03-05 CVE-2025-1008 The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘view’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping.
6.4
2025-03-03 CVE-2025-0684 A flaw was found in grub2.
6.4
2025-03-03 CVE-2025-0685 A flaw was found in grub2.
6.4
2025-03-03 CVE-2025-0686 A flaw was found in grub2.
6.4
2025-03-09 CVE-2025-2117 A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical.
6.3
2025-03-08 CVE-2025-1325 Plechevandrey Missing Authorization vulnerability in Plechevandrey Wp-Recall

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to, and including, 16.26.10.

6.3
2025-03-08 CVE-2024-13895 Jtsternberg Code Injection vulnerability in Jtsternberg Code Snippets CPT

The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0.

6.3
2025-03-07 CVE-2025-2051 A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical.
6.3
2025-03-07 CVE-2025-2052 A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical.
6.3
2025-03-07 CVE-2025-2053 A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0.
6.3
2025-03-06 CVE-2025-2041 A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0.
6.3
2025-03-06 CVE-2025-2040 A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1.
6.3
2025-03-06 CVE-2025-2036 A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0.
6.3
2025-03-06 CVE-2025-2037 A vulnerability was found in code-projects Blood Bank Management System 1.0.
6.3
2025-03-06 CVE-2025-2035 A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical.
6.3
2025-03-06 CVE-2025-2033 A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0.
6.3
2025-03-05 CVE-2025-1435 The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11.
6.3
2025-03-04 CVE-2025-1946 A vulnerability was found in hzmanyun Education and Training System 2.1.
6.3
2025-03-04 CVE-2025-1947 A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3.
6.3
2025-03-04 CVE-2025-0958 Auctionplugin Improper Input Validation vulnerability in Auctionplugin Ultimate Auction

The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9.

6.3
2025-03-03 CVE-2025-1854 A vulnerability was found in Codezips Gym Management System 1.0.
6.3
2025-03-03 CVE-2025-1855 A vulnerability was found in PHPGurukul Online Shopping Portal 2.1.
6.3
2025-03-03 CVE-2024-8262 Prolizyazilim Unspecified vulnerability in Prolizyazilim Student Affairs Information System 23.04.01

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.

6.2
2025-03-09 CVE-2025-2127 Joomlaux Code Injection vulnerability in Joomlaux JUX Real Estate 3.4.0

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla.

6.1
2025-03-07 CVE-2023-35894 IBM Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability in IBM Sterling Control Center 6.2.1/6.3.1

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.

6.1
2025-03-07 CVE-2025-2086 Starsea99 Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0

A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0.

6.1
2025-03-07 CVE-2025-2087 Starsea99 Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0

A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0.

6.1
2025-03-07 CVE-2025-2084 Phpgurukul Code Injection vulnerability in PHPgurukul Human Metapneumovirus 1.0

A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.

6.1
2025-03-07 CVE-2025-2085 Starsea99 Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0

A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0.

6.1
2025-03-07 CVE-2024-12634 The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59.
6.1
2025-03-07 CVE-2024-13431 Nsquared Cross-site Scripting vulnerability in Nsquared Appointment Booking Calendar

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping.

6.1
2025-03-05 CVE-2024-13779 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions up to, and including, 1.16.5 due to insufficient input sanitization and output escaping.
6.1
2025-03-05 CVE-2024-13839 The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3.
6.1
2025-03-05 CVE-2024-13827 The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() and remove_query_arg() functions without appropriate escaping on the URL in all versions up to, and including, 1.0.3.
6.1
2025-03-04 CVE-2025-1904 Code Projects Unspecified vulnerability in Code-Projects Blood Bank System 1.0

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0.

6.1
2025-03-04 CVE-2025-1905 Remyandrade Unspecified vulnerability in Remyandrade Employee Management System 1.0

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0.

6.1
2025-03-03 CVE-2025-25939 Reprisesoftware Unspecified vulnerability in Reprisesoftware License Manager 14.2

Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

6.1
2025-03-03 CVE-2025-27499 Wegia Unspecified vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

6.1
2025-03-03 CVE-2025-27500 Openziti Cross-site Scripting vulnerability in Openziti

OpenZiti is a free and open source project focused on bringing zero trust to any application.

6.1
2025-03-03 CVE-2025-0555 Gitlab Cross-site Scripting vulnerability in Gitlab

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

6.1
2025-03-03 CVE-2025-23526 Swiftcloud Cross-site Scripting vulnerability in Swiftcloud Swift Calendar Online Appointment Scheduling

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Swift Calendar Online Appointment Scheduling allows Reflected XSS.

6.1
2025-03-03 CVE-2025-26917 Hasthemes Cross-site Scripting vulnerability in Hasthemes WP Templata

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS.

6.1
2025-03-03 CVE-2025-26918 Eniture Cross-site Scripting vulnerability in Eniture Small Package Quotes

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Unishippers Edition allows Reflected XSS.

6.1
2025-03-03 CVE-2025-26984 Cozyvision Cross-site Scripting vulnerability in Cozyvision SMS Alert Order Notifications

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS.

6.1
2025-03-03 CVE-2025-26989 Softdiscover Cross-site Scripting vulnerability in Softdiscover Zigaform

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Form Builder Lite allows Stored XSS.

6.1
2025-03-03 CVE-2025-26994 Softdiscover Cross-site Scripting vulnerability in Softdiscover Zigaform

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite allows Stored XSS.

6.1
2025-03-03 CVE-2025-0475 Gitlab Cross-site Scripting vulnerability in Gitlab

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1.

6.1
2025-03-04 CVE-2025-22226 Vmware Unspecified vulnerability in VMWare products

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

6.0
2025-03-03 CVE-2024-45779 GNU Unspecified vulnerability in GNU Grub2

An integer overflow flaw was found in the BFS file system driver in grub2.

6.0
2025-03-08 CVE-2024-13640 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory.
5.9
2025-03-03 CVE-2024-8261 Prolizyazilim Unspecified vulnerability in Prolizyazilim Student Affairs Information System 23.04.01

Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927.

5.9
2025-03-09 CVE-2025-2129 A vulnerability was found in Mage AI 0.9.75.
5.6
2025-03-07 CVE-2024-13857 The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.10.
5.5
2025-03-07 CVE-2025-21843 Linux Use of Uninitialized Resource vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the uninitialized value is copied to user object when calling PANTHOR_UOBJ_SET().

5.5
2025-03-06 CVE-2024-58076 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-sm6350: Add missing parent_map for two clocks If a clk_rcg2 has a parent, it should also have parent_map defined, otherwise we'll get a NULL pointer dereference when calling clk_set_rate like the following: [ 3.388105] Call trace: [ 3.390664] qcom_find_src_index+0x3c/0x70 (P) [ 3.395301] qcom_find_src_index+0x1c/0x70 (L) [ 3.399934] _freq_tbl_determine_rate+0x48/0x100 [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28 [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4 [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300 [ 3.455886] clk_set_rate+0x38/0x14c Add the parent_map property for two clocks where it's missing and also un-inline the parent_data as well to keep the matching parent_map and parent_data together.

5.5
2025-03-06 CVE-2024-58080 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-sm6350: Add missing parent_map for a clock If a clk_rcg2 has a parent, it should also have parent_map defined, otherwise we'll get a NULL pointer dereference when calling clk_set_rate like the following: [ 3.388105] Call trace: [ 3.390664] qcom_find_src_index+0x3c/0x70 (P) [ 3.395301] qcom_find_src_index+0x1c/0x70 (L) [ 3.399934] _freq_tbl_determine_rate+0x48/0x100 [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28 [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4 [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300 [ 3.455886] clk_set_rate+0x38/0x14c Add the parent_map property for the clock where it's missing and also un-inline the parent_data as well to keep the matching parent_map and parent_data together.

5.5
2025-03-06 CVE-2024-58081 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.name is set Setting the genpd's struct device's name with dev_set_name() is happening within pm_genpd_init().

5.5
2025-03-06 CVE-2024-58084 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit 2e4955167ec5 ("firmware: qcom: scm: Fix __scm and waitq completion variable initialization") introduced a write barrier in probe function to store global '__scm' variable.

5.5
2025-03-06 CVE-2025-21833 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE There is a WARN_ON_ONCE to catch an unlikely situation when domain_remove_dev_pasid can't find the `pasid`.

5.5
2025-03-06 CVE-2024-58052 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table The function atomctrl_get_smc_sclk_range_table() does not check the return value of smu_atom_get_data_table().

5.5
2025-03-06 CVE-2024-58058 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ubifs: skip dumping tnc tree when zroot is null Clearing slab cache will free all znode in memory and make c->zroot.znode = NULL, then dumping tnc tree will access c->zroot.znode which cause null pointer dereference.

5.5
2025-03-06 CVE-2024-58059 Linux Improper Locking vulnerability in Linux Kernel 6.13/6.13.1

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix deadlock during uvc_probe If uvc_probe() fails, it can end up calling uvc_status_unregister() before uvc_status_init() is called. Fix this by checking if dev->status is NULL or not in uvc_status_unregister().

5.5
2025-03-06 CVE-2024-58062 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: avoid NULL pointer dereference When iterating over the links of a vif, we need to make sure that the pointer is valid (in other words - that the link exists) before dereferncing it. Use for_each_vif_active_link that also does the check.

5.5
2025-03-06 CVE-2024-58063 Linux Memory Leak vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: fix memory leaks and invalid access at probe error path Deinitialize at reverse order when probe fails. When init_sw_vars fails, rtl_deinit_core should not be called, specially now that it destroys the rtl_wq workqueue. And call rtl_pci_deinit and deinit_sw_vars, otherwise, memory will be leaked. Remove pci_set_drvdata call as it will already be cleaned up by the core driver code and could lead to memory leaks too.

5.5
2025-03-06 CVE-2024-58064 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: tests: Fix potential NULL dereference in test_cfg80211_parse_colocated_ap() kunit_kzalloc() may return NULL, dereferencing it without NULL check may lead to NULL dereference. Add a NULL check for ies.

5.5
2025-03-06 CVE-2024-58065 Linux NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1

In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() check The devm_kzalloc() function returns NULL on error, not error pointers. Fix the check.

5.5
2025-03-06 CVE-2024-58066 Linux NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1

In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() check The devm_kzalloc() function doesn't return error pointers, it returns NULL on error.

5.5
2025-03-06 CVE-2024-58067 Linux NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1

In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() check The devm_kzalloc() function returns NULL on error, not error pointers. Update the check to match.

5.5
2025-03-06 CVE-2024-58068 Linux NULL Pointer Dereference vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized If a driver calls dev_pm_opp_find_bw_ceil/floor() the retrieve bandwidth from the OPP table but the bandwidth table was not created because the interconnect properties were missing in the OPP consumer node, the kernel will crash with: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004 ... pc : _read_bw+0x8/0x10 lr : _opp_table_find_key+0x9c/0x174 ... Call trace: _read_bw+0x8/0x10 (P) _opp_table_find_key+0x9c/0x174 (L) _find_key+0x98/0x168 dev_pm_opp_find_bw_ceil+0x50/0x88 ... In order to fix the crash, create an assert function to check if the bandwidth table was created before trying to get a bandwidth with _read_bw().

5.5
2025-03-06 CVE-2024-58070 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT In PREEMPT_RT, kmalloc(GFP_ATOMIC) is still not safe in non preemptible context.

5.5
2025-03-06 CVE-2024-58071 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, e.g.

5.5
2025-03-06 CVE-2024-58073 Linux NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: check dpu_plane_atomic_print_state() for valid sspp Similar to the r_pipe sspp protect, add a check to protect the pipe state prints to avoid NULL ptr dereference for cases when the state is dumped without a corresponding atomic_check() where the pipe->sspp is assigned. Patchwork: https://patchwork.freedesktop.org/patch/628404/

5.5
2025-03-06 CVE-2025-1672 The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping.
5.5
2025-03-04 CVE-2024-58043 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2024-58044 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

5.5
2025-03-04 CVE-2024-58046 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2024-58047 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2024-58049 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2024-58050 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2025-27521 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2025-03-04 CVE-2025-20011 Openatom Memory Leak vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

5.5
2025-03-04 CVE-2025-20021 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-04 CVE-2025-20042 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

5.5
2025-03-04 CVE-2025-21089 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-04 CVE-2025-21097 Openatom NULL Pointer Dereference vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

5.5
2025-03-04 CVE-2025-21098 Openatom Insecure Storage of Sensitive Information vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.

5.5
2025-03-04 CVE-2025-22443 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-04 CVE-2025-22837 Openatom NULL Pointer Dereference vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

5.5
2025-03-04 CVE-2025-22841 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-04 CVE-2025-22847 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-04 CVE-2025-22897 Openatom Classic Buffer Overflow vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

5.5
2025-03-04 CVE-2025-23234 Openatom Classic Buffer Overflow vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

5.5
2025-03-04 CVE-2025-23418 Openatom Out-of-bounds Read vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

5.5
2025-03-03 CVE-2024-45778 GNU
Redhat
Integer Overflow or Wraparound vulnerability in multiple products

A stack overflow flaw was found when reading a BFS file system.

5.5
2025-03-03 CVE-2024-43051 Qualcomm Improper Authorization vulnerability in Qualcomm products

Information disclosure while deriving keys for a session for any Widevine use case.

5.5
2025-03-03 CVE-2024-53025 Qualcomm Integer Overflow or Wraparound vulnerability in Qualcomm products

Transient DOS can occur while processing UCI command.

5.5
2025-03-09 CVE-2025-2130 Openxe Cross-site Scripting vulnerability in Openxe

A vulnerability was found in OpenXE up to 1.12.

5.4
2025-03-08 CVE-2024-13649 Wpxpro Cross-site Scripting vulnerability in Wpxpro Xpro Addons for Elementor

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2024-13675 Funnelkit Cross-site Scripting vulnerability in Funnelkit Slingblocks

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2025-1664 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2025-1324 Plechevandrey Cross-site Scripting vulnerability in Plechevandrey Wp-Recall

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-03-08 CVE-2025-1783 Tiptoppress Cross-site Scripting vulnerability in Tiptoppress Gallery Styles

The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2024-13816 Coderevolution Missing Authorization vulnerability in Coderevolution Aiomatic

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6.

5.4
2025-03-08 CVE-2025-1287 Posimyth Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2024-12119 Fooplugins Cross-site Scripting vulnerability in Fooplugins Foogallery

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping.

5.4
2025-03-08 CVE-2025-1261 Hasthemes Cross-site Scripting vulnerability in Hasthemes HT Mega

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-03-07 CVE-2025-26643 Microsoft Unspecified vulnerability in Microsoft Edge Chromium

The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

5.4
2025-03-05 CVE-2025-20208 Cisco Cross-site Scripting vulnerability in Cisco Telepresence Management Suite 15.13.6

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

5.4
2025-03-05 CVE-2024-12650 An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area.
5.4
2025-03-04 CVE-2025-0370 Vanokhin Cross-site Scripting vulnerability in Vanokhin Shortcodes Ultimate

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping.

5.4
2025-03-04 CVE-2024-9618 Master Addons Cross-site Scripting vulnerability in Master-Addons Master Addons

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.7.2 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-03-04 CVE-2025-0433 Master Addons Cross-site Scripting vulnerability in Master-Addons Master Addons

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping.

5.4
2025-03-04 CVE-2025-0512 Wpsc Plugin Cross-site Scripting vulnerability in Wpsc-Plugin Structured Content

The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-03-03 CVE-2024-55064 Easyvirt Unspecified vulnerability in Easyvirt DC Netscope

Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter.

5.4
2025-03-03 CVE-2024-54179 IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting.
5.4
2025-03-03 CVE-2024-8186 Gitlab Cross-site Scripting vulnerability in Gitlab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1.

5.4
2025-03-07 CVE-2023-43052 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input.
5.3
2025-03-07 CVE-2024-12610 The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0.
5.3
2025-03-07 CVE-2024-12611 The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping.
5.3
2025-03-06 CVE-2025-2029 A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321.
5.3
2025-03-05 CVE-2024-11153 The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search feature.
5.3
2025-03-05 CVE-2024-13423 The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9.
5.3
2025-03-05 CVE-2024-8682 The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6.
5.3
2025-03-04 CVE-2025-1925 A vulnerability classified as problematic was found in Open5GS up to 2.7.2.
5.3
2025-03-04 CVE-2025-20024 Openatom Integer Overflow or Wraparound vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

5.3
2025-03-04 CVE-2025-20081 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

5.3
2025-03-04 CVE-2025-27221 TAL Unspecified vulnerability in TAL URL

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

5.3
2025-03-03 CVE-2025-24023 Dpgaspar Response Discrepancy Information Exposure vulnerability in Dpgaspar Flask-Appbuilder

Flask-AppBuilder is an application development framework.

5.3
2025-03-03 CVE-2024-38426 Qualcomm Improper Authentication vulnerability in Qualcomm products

While processing the authentication message in UE, improper authentication may lead to information disclosure.

5.3
2025-03-08 CVE-2024-13844 Wpexperts SQL Injection vulnerability in Wpexperts Post Smtp

The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

4.9
2025-03-03 CVE-2024-51958 Esri Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3.

4.9
2025-03-03 CVE-2024-51966 Esri Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3.

4.9
2025-03-03 CVE-2025-27274 Axelkeller Path Traversal: '.../...//' vulnerability in Axelkeller GPX Viewer

Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal.

4.9
2025-03-09 CVE-2025-2131 Xunruicms Code Injection vulnerability in Xunruicms

A vulnerability was found in dayrui XunRuiCMS up to 4.6.3.

4.8
2025-03-04 CVE-2025-1892 Qzw1210 Unspecified vulnerability in Qzw1210 Shishuocms 1.1

A vulnerability was found in shishuocms 1.1.

4.8
2025-03-03 CVE-2024-10904 Esri Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

4.8
2025-03-03 CVE-2024-51942 Esri Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

4.8
2025-03-03 CVE-2024-51944 Esri Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.

4.8
2025-03-07 CVE-2025-2054 A vulnerability was found in code-projects Blood Bank Management System 1.0.
4.7
2025-03-06 CVE-2025-2043 A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical.
4.7
2025-03-06 CVE-2025-2044 A vulnerability was found in code-projects Blood Bank Management System 1.0.
4.7
2025-03-06 CVE-2025-2039 A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0.
4.7
2025-03-06 CVE-2025-0877 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS).This issue affects Reservation Management System: before 4.2.3.
4.7
2025-03-04 CVE-2024-58045 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

4.7
2025-03-04 CVE-2024-58048 Huawei Unspecified vulnerability in Huawei Harmonyos 5.0.0

Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability.

4.7
2025-03-09 CVE-2025-2125 Assaabloy Resource Injection vulnerability in Assaabloy Control ID Rhid 25.2.25.0

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic.

4.3
2025-03-09 CVE-2025-2116 A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic.
4.3
2025-03-08 CVE-2024-10326 Rometheme Missing Authorization vulnerability in Rometheme Romethemekit for Elementor

The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3.

4.3
2025-03-08 CVE-2025-1322 Plechevandrey Information Exposure vulnerability in Plechevandrey Wp-Recall

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included.

4.3
2025-03-08 CVE-2024-10321 Themesgrove Information Exposure vulnerability in Themesgrove All-In-One Addons for Elementor

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/advanced-tab/template/view.php.

4.3
2025-03-08 CVE-2024-12114 Fooplugins Authorization Bypass Through User-Controlled Key vulnerability in Fooplugins Foogallery

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id).

4.3
2025-03-08 CVE-2025-1481 Jozoor Missing Authorization vulnerability in Jozoor Shortcode Cleaner Lite

The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1.0.9.

4.3
2025-03-07 CVE-2024-13552 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled key.
4.3
2025-03-07 CVE-2024-13635 The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block.
4.3
2025-03-07 CVE-2025-2061 A vulnerability was found in code-projects Online Ticket Reservation System 1.0.
4.3
2025-03-07 CVE-2024-13526 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3.
4.3
2025-03-07 CVE-2025-0748 The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3.
4.3
2025-03-06 CVE-2025-2042 A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic.
4.3
2025-03-06 CVE-2025-1383 Podlove Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2.

4.3
2025-03-06 CVE-2025-1666 The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1.
4.3
2025-03-05 CVE-2025-1463 The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2.
4.3
2025-03-05 CVE-2024-13747 The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'template_delete_saved' function in all versions up to, and including, 3.0.34.
4.3
2025-03-05 CVE-2024-13810 The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'zass_import_zass' AJAX actions in all versions up to, and including, 3.9.9.10.
4.3
2025-03-05 CVE-2024-13811 The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7.
4.3
2025-03-05 CVE-2025-0990 The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.4.
4.3
2025-03-04 CVE-2024-13682 Wpswings Cross-Site Request Forgery (CSRF) vulnerability in Wpswings Wallet System for Woocommerce

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2.

4.3
2025-03-04 CVE-2024-13724 Wpswings Improper Authorization vulnerability in Wpswings Wallet System for Woocommerce

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2.

4.3
2025-03-04 CVE-2024-13686 The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9.
4.3
2025-03-03 CVE-2025-1881 I Drive Incorrect Privilege Assignment vulnerability in I-Drive I11 Firmware and I12 Firmware

A vulnerability was found in i-Drive i11 and i12 up to 20250227.

4.3
2025-03-03 CVE-2025-1880 I Drive Authentication Bypass by Primary Weakness vulnerability in I-Drive I11 Firmware and I12 Firmware

A vulnerability was found in i-Drive i11 and i12 up to 20250227.

4.3
2025-03-03 CVE-2025-1842 A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302.
4.3

8 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-09 CVE-2025-2114 A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7.
3.7
2025-03-09 CVE-2025-2124 A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0.
3.5
2025-03-06 CVE-2025-2032 A vulnerability classified as problematic was found in ChestnutCMS 1.5.2.
3.5
2025-03-04 CVE-2025-1955 A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0.
3.5
2025-03-03 CVE-2025-1878 I Drive Unspecified vulnerability in I-Drive I11 Firmware and I12 Firmware

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic.

3.1
2025-03-04 CVE-2025-1953 A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic.
2.6
2025-03-06 CVE-2024-13902 A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0.
2.4
2025-03-09 CVE-2025-2119 A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226.
2.0