Weekly Vulnerabilities Reports > March 3 to 9, 2025
Overview
378 new vulnerabilities reported during this period, including 54 critical vulnerabilities and 116 high severity vulnerabilities. This weekly summary report vulnerabilities in 534 products from 98 vendors including Openatom, Qualcomm, Linux, Phpgurukul, and Huawei. Vulnerabilities are notably categorized as "Cross-site Scripting", "Injection", "SQL Injection", "Missing Authorization", and "NULL Pointer Dereference".
- 275 reported vulnerabilities are remotely exploitables.
- 104 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 166 reported vulnerabilities are exploitable by an anonymous user.
- Openatom has the most reported vulnerabilities, with 26 reported vulnerabilities.
- Phpgurukul has the most reported critical vulnerabilities, with 9 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
54 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-03-08 | CVE-2024-13359 | Tychesoftwares | Unrestricted Upload of File with Dangerous Type vulnerability in Tychesoftwares Product Input Fields for Woocommerce The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to_order_item_meta() function in all versions up to, and including, 1.12.0. | 9.8 |
2025-03-08 | CVE-2025-1323 | Plechevandrey | SQL Injection vulnerability in Plechevandrey Wp-Recall The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 9.8 |
2025-03-08 | CVE-2025-0177 | Javothemes | Improper Privilege Management vulnerability in Javothemes Javo Core The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. | 9.8 |
2025-03-08 | CVE-2024-11087 | Miniorange | Improper Authentication vulnerability in Miniorange Social Login The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. | 9.8 |
2025-03-07 | CVE-2025-2097 | Totolink | Out-of-bounds Write vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316 A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. | 9.8 |
2025-03-07 | CVE-2025-2094 | Totolink | OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316 A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. | 9.8 |
2025-03-07 | CVE-2025-2095 | Totolink | OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316 A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. | 9.8 |
2025-03-07 | CVE-2025-2096 | Totolink | OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316 A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. | 9.8 |
2025-03-07 | CVE-2025-2088 | Phpgurukul | Injection vulnerability in PHPgurukul Pre-School Enrollment System 1.0 A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. | 9.8 |
2025-03-07 | CVE-2024-12876 | Uxper | Missing Authorization vulnerability in Uxper Golo The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. | 9.8 |
2025-03-07 | CVE-2025-1315 | Sfwebservice | Authentication Bypass Using an Alternate Path or Channel vulnerability in Sfwebservice Injob The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. | 9.8 |
2025-03-07 | CVE-2025-1475 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. | 9.8 | |
2025-03-06 | CVE-2024-12144 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection.This issue affects Finder ERP/CRM (Old System): before 18.12.2024. | 9.8 | |
2025-03-05 | CVE-2024-12097 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informatics E-Travel allows SQL Injection.This issue affects E-Travel: before 15.12.2024. | 9.8 | |
2025-03-05 | CVE-2024-13147 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection.This issue affects B2B Login Panel: before 15.01.2025. | 9.8 | |
2025-03-05 | CVE-2024-11951 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. | 9.8 | |
2025-03-05 | CVE-2024-12281 | The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. | 9.8 | |
2025-03-05 | CVE-2024-13787 | The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. | 9.8 | |
2025-03-05 | CVE-2025-1515 | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. | 9.8 | |
2025-03-05 | CVE-2025-1393 | An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product. | 9.8 | |
2025-03-05 | CVE-2025-1966 | Phpgurukul | Unspecified vulnerability in PHPgurukul Pre-School Enrollment System 1.0 A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. | 9.8 |
2025-03-05 | CVE-2025-1965 | Projectworlds | SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0 A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. | 9.8 |
2025-03-05 | CVE-2025-1316 | Edimax | OS Command Injection vulnerability in Edimax Ic-7100 Firmware Edimax IC-7100 does not properly neutralize requests. | 9.8 |
2025-03-05 | CVE-2025-1962 | Projectworlds | SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0 A vulnerability was found in projectworlds Online Hotel Booking 1.0. | 9.8 |
2025-03-05 | CVE-2025-1963 | Projectworlds | SQL Injection vulnerability in Projectworlds Online Hotel Booking 1.0 A vulnerability was found in projectworlds Online Hotel Booking 1.0. | 9.8 |
2025-03-04 | CVE-2025-1959 | Codezips | Unspecified vulnerability in Codezips GYM Management System 1.0 A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. | 9.8 |
2025-03-04 | CVE-2025-1956 | Code Projects | Injection vulnerability in Code-Projects Shopping Portal 1.0 A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. | 9.8 |
2025-03-04 | CVE-2025-1952 | Phpgurukul | Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0 A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. | 9.8 |
2025-03-04 | CVE-2025-1307 | Spicethemes | Missing Authorization vulnerability in Spicethemes Newscrunch The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. | 9.8 |
2025-03-04 | CVE-2025-1906 | Phpgurukul | Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0 A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. | 9.8 |
2025-03-04 | CVE-2025-0912 | Givewp | Deserialization of Untrusted Data vulnerability in Givewp The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. | 9.8 |
2025-03-04 | CVE-2025-1900 | Phpgurukul | Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0 A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. | 9.8 |
2025-03-04 | CVE-2025-1901 | Phpgurukul | Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0 A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. | 9.8 |
2025-03-04 | CVE-2025-1902 | Phpgurukul | Unspecified vulnerability in PHPgurukul Student Record System 3.2 A vulnerability was found in PHPGurukul Student Record System 3.2. | 9.8 |
2025-03-04 | CVE-2025-1903 | Codezips | Unspecified vulnerability in Codezips Online Shopping Website 1.0 A vulnerability was found in Codezips Online Shopping Website 1.0. | 9.8 |
2025-03-04 | CVE-2025-1894 | Phpgurukul | Injection vulnerability in PHPgurukul Restaurant Table Booking System 1.0 A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. | 9.8 |
2025-03-04 | CVE-2025-1890 | Shishuocms Project | Unrestricted Upload of File with Dangerous Type vulnerability in Shishuocms Project Shishuocms 1.1 A vulnerability has been found in shishuocms 1.1 and classified as critical. | 9.8 |
2025-03-03 | CVE-2025-1889 | Mmaitre314 | Unspecified vulnerability in Mmaitre314 Picklescan picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. | 9.8 |
2025-03-03 | CVE-2025-26970 | Arktheme | Code Injection vulnerability in Arktheme the ARK Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Ark Theme Core allows Code Injection. | 9.8 |
2025-03-03 | CVE-2025-1869 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php. | 9.8 |
2025-03-03 | CVE-2025-1870 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php. | 9.8 |
2025-03-03 | CVE-2025-1871 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php. | 9.8 |
2025-03-03 | CVE-2025-1872 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php. | 9.8 |
2025-03-03 | CVE-2025-1873 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php. | 9.8 |
2025-03-03 | CVE-2025-1874 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php. | 9.8 |
2025-03-03 | CVE-2025-1875 | Mayurik | SQL Injection vulnerability in Mayurik Best Online News Portal 1.0 SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php. | 9.8 |
2025-03-03 | CVE-2025-1859 | Phpgurukul | Injection vulnerability in PHPgurukul News Portal 4.1 A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. | 9.8 |
2025-03-03 | CVE-2025-1852 | Totolink | Classic Buffer Overflow vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316 A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. | 9.8 |
2025-03-03 | CVE-2025-1853 | Tenda | Stack-based Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06 A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. | 9.8 |
2025-03-03 | CVE-2025-1850 | Codezips | Unspecified vulnerability in Codezips College Management System 1.0 A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. | 9.8 |
2025-03-03 | CVE-2025-27590 | Oxidized WEB Project | Unspecified vulnerability in Oxidized web Project Oxidized web In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. | 9.8 |
2025-03-03 | CVE-2024-51962 | Esri | SQL Injection vulnerability in Esri Arcgis Server 10.9.1/11.1 A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges. There is a high impact to integrity and confidentiality and no impact to availability. | 9.6 |
2025-03-08 | CVE-2024-13924 | Fancywp | Server-Side Request Forgery (SSRF) vulnerability in Fancywp Starter Templates The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. | 9.1 |
2025-03-07 | CVE-2024-13904 | Platformly | Server-Side Request Forgery (SSRF) vulnerability in Platformly Platform.Ly for Woocommerce The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. | 9.1 |
116 High Vulnerabilities
200 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-03-08 | CVE-2025-27840 | Espressif | Unspecified vulnerability in Espressif Esp32 Firmware Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory). | 6.8 |
2025-03-03 | CVE-2025-1879 | I Drive | Use of Hard-coded Password vulnerability in I-Drive I11 Firmware and I12 Firmware A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. | 6.8 |
2025-03-03 | CVE-2024-45780 | GNU | Unspecified vulnerability in GNU Grub2 A flaw was found in grub2. | 6.7 |
2025-03-08 | CVE-2024-13774 | Wpfactory | Cross-Site Request Forgery (CSRF) vulnerability in Wpfactory Wishlist for Woocommerce The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. | 6.5 |
2025-03-08 | CVE-2025-1504 | Andypalmer | Missing Authorization vulnerability in Andypalmer Post Lockdown The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due to insufficient restrictions on which posts can be included. | 6.5 |
2025-03-07 | CVE-2025-1768 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to, and including, 12.4.05 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 | |
2025-03-07 | CVE-2024-12607 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 | |
2025-03-07 | CVE-2024-12609 | The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the mj_smgt_view_student_attendance() function. | 6.5 | |
2025-03-07 | CVE-2024-13781 | Heroplugins | SQL Injection vulnerability in Heroplugins Hero Maps Premium The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-03-07 | CVE-2025-0959 | Imithemes | SQL Injection: Hibernate vulnerability in Imithemes Eventer The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-03-06 | CVE-2024-13897 | The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_page function in all versions up to, and including, 1.22. | 6.5 | |
2025-03-05 | CVE-2024-13778 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several functions in all versions up to, and including, 1.16.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 | |
2025-03-05 | CVE-2024-13780 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5. | 6.5 | |
2025-03-05 | CVE-2024-13809 | The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 | |
2025-03-05 | CVE-2024-13815 | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. | 6.5 | |
2025-03-05 | CVE-2025-0954 | The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the json_import() and json_export() functions in all versions up to, and including, 5.1.4. | 6.5 | |
2025-03-03 | CVE-2025-25302 | Danielgatis | Origin Validation Error vulnerability in Danielgatis Rembg Rembg is a tool to remove images background. | 6.5 |
2025-03-03 | CVE-2024-43169 | IBM | Download of Code Without Integrity Check vulnerability in IBM Engineering Requirements Management Doors Next 7.0.2/7.0.3/7.1 IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code. | 6.5 |
2025-03-03 | CVE-2024-43056 | Qualcomm | Buffer Over-read vulnerability in Qualcomm products Transient DOS during hypervisor virtual I/O operation in a virtual machine. | 6.5 |
2025-03-08 | CVE-2024-12460 | The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-07 | CVE-2024-13805 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-03-07 | CVE-2025-0863 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-07 | CVE-2024-12809 | The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-11731 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_slider shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-12815 | The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortcode in all versions up to, and including, 0.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-13757 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-5667 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js JavaScript library (versions 1.7.13 to 1.7.14) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-13350 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-03-05 | CVE-2024-13866 | The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-03-05 | CVE-2025-1008 | The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘view’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-03-03 | CVE-2025-0684 | A flaw was found in grub2. | 6.4 | |
2025-03-03 | CVE-2025-0685 | A flaw was found in grub2. | 6.4 | |
2025-03-03 | CVE-2025-0686 | A flaw was found in grub2. | 6.4 | |
2025-03-09 | CVE-2025-2117 | A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. | 6.3 | |
2025-03-08 | CVE-2025-1325 | Plechevandrey | Missing Authorization vulnerability in Plechevandrey Wp-Recall The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to, and including, 16.26.10. | 6.3 |
2025-03-08 | CVE-2024-13895 | Jtsternberg | Code Injection vulnerability in Jtsternberg Code Snippets CPT The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. | 6.3 |
2025-03-07 | CVE-2025-2051 | A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. | 6.3 | |
2025-03-07 | CVE-2025-2052 | A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. | 6.3 | |
2025-03-07 | CVE-2025-2053 | A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. | 6.3 | |
2025-03-06 | CVE-2025-2041 | A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. | 6.3 | |
2025-03-06 | CVE-2025-2040 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. | 6.3 | |
2025-03-06 | CVE-2025-2036 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. | 6.3 | |
2025-03-06 | CVE-2025-2037 | A vulnerability was found in code-projects Blood Bank Management System 1.0. | 6.3 | |
2025-03-06 | CVE-2025-2035 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. | 6.3 | |
2025-03-06 | CVE-2025-2033 | A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. | 6.3 | |
2025-03-05 | CVE-2025-1435 | The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. | 6.3 | |
2025-03-04 | CVE-2025-1946 | A vulnerability was found in hzmanyun Education and Training System 2.1. | 6.3 | |
2025-03-04 | CVE-2025-1947 | A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. | 6.3 | |
2025-03-04 | CVE-2025-0958 | Auctionplugin | Improper Input Validation vulnerability in Auctionplugin Ultimate Auction The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. | 6.3 |
2025-03-03 | CVE-2025-1854 | A vulnerability was found in Codezips Gym Management System 1.0. | 6.3 | |
2025-03-03 | CVE-2025-1855 | A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. | 6.3 | |
2025-03-03 | CVE-2024-8262 | Prolizyazilim | Unspecified vulnerability in Prolizyazilim Student Affairs Information System 23.04.01 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927. | 6.2 |
2025-03-09 | CVE-2025-2127 | Joomlaux | Code Injection vulnerability in Joomlaux JUX Real Estate 3.4.0 A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. | 6.1 |
2025-03-07 | CVE-2023-35894 | IBM | Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability in IBM Sterling Control Center 6.2.1/6.3.1 IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. | 6.1 |
2025-03-07 | CVE-2025-2086 | Starsea99 | Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0 A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. | 6.1 |
2025-03-07 | CVE-2025-2087 | Starsea99 | Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0 A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. | 6.1 |
2025-03-07 | CVE-2025-2084 | Phpgurukul | Code Injection vulnerability in PHPgurukul Human Metapneumovirus 1.0 A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. | 6.1 |
2025-03-07 | CVE-2025-2085 | Starsea99 | Code Injection vulnerability in Starsea99 Starsea-Mall 1.0.0 A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. | 6.1 |
2025-03-07 | CVE-2024-12634 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. | 6.1 | |
2025-03-07 | CVE-2024-13431 | Nsquared | Cross-site Scripting vulnerability in Nsquared Appointment Booking Calendar The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. | 6.1 |
2025-03-05 | CVE-2024-13779 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions up to, and including, 1.16.5 due to insufficient input sanitization and output escaping. | 6.1 | |
2025-03-05 | CVE-2024-13839 | The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3. | 6.1 | |
2025-03-05 | CVE-2024-13827 | The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() and remove_query_arg() functions without appropriate escaping on the URL in all versions up to, and including, 1.0.3. | 6.1 | |
2025-03-04 | CVE-2025-1904 | Code Projects | Unspecified vulnerability in Code-Projects Blood Bank System 1.0 A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. | 6.1 |
2025-03-04 | CVE-2025-1905 | Remyandrade | Unspecified vulnerability in Remyandrade Employee Management System 1.0 A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. | 6.1 |
2025-03-03 | CVE-2025-25939 | Reprisesoftware | Unspecified vulnerability in Reprisesoftware License Manager 14.2 Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter. | 6.1 |
2025-03-03 | CVE-2025-27499 | Wegia | Unspecified vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 6.1 |
2025-03-03 | CVE-2025-27500 | Openziti | Cross-site Scripting vulnerability in Openziti OpenZiti is a free and open source project focused on bringing zero trust to any application. | 6.1 |
2025-03-03 | CVE-2025-0555 | Gitlab | Cross-site Scripting vulnerability in Gitlab A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions. | 6.1 |
2025-03-03 | CVE-2025-23526 | Swiftcloud | Cross-site Scripting vulnerability in Swiftcloud Swift Calendar Online Appointment Scheduling Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Swift Calendar Online Appointment Scheduling allows Reflected XSS. | 6.1 |
2025-03-03 | CVE-2025-26917 | Hasthemes | Cross-site Scripting vulnerability in Hasthemes WP Templata Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS. | 6.1 |
2025-03-03 | CVE-2025-26918 | Eniture | Cross-site Scripting vulnerability in Eniture Small Package Quotes Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Unishippers Edition allows Reflected XSS. | 6.1 |
2025-03-03 | CVE-2025-26984 | Cozyvision | Cross-site Scripting vulnerability in Cozyvision SMS Alert Order Notifications Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. | 6.1 |
2025-03-03 | CVE-2025-26989 | Softdiscover | Cross-site Scripting vulnerability in Softdiscover Zigaform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Form Builder Lite allows Stored XSS. | 6.1 |
2025-03-03 | CVE-2025-26994 | Softdiscover | Cross-site Scripting vulnerability in Softdiscover Zigaform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite allows Stored XSS. | 6.1 |
2025-03-03 | CVE-2025-0475 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. | 6.1 |
2025-03-04 | CVE-2025-22226 | Vmware | Unspecified vulnerability in VMWare products VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | 6.0 |
2025-03-03 | CVE-2024-45779 | GNU | Unspecified vulnerability in GNU Grub2 An integer overflow flaw was found in the BFS file system driver in grub2. | 6.0 |
2025-03-08 | CVE-2024-13640 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. | 5.9 | |
2025-03-03 | CVE-2024-8261 | Prolizyazilim | Unspecified vulnerability in Prolizyazilim Student Affairs Information System 23.04.01 Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927. | 5.9 |
2025-03-09 | CVE-2025-2129 | A vulnerability was found in Mage AI 0.9.75. | 5.6 | |
2025-03-07 | CVE-2024-13857 | The WPGet API – Connect to any external REST API plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.10. | 5.5 | |
2025-03-07 | CVE-2025-21843 | Linux | Use of Uninitialized Resource vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_dev_query() 'priorities_info' is uninitialized, and the uninitialized value is copied to user object when calling PANTHOR_UOBJ_SET(). | 5.5 |
2025-03-06 | CVE-2024-58076 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gcc-sm6350: Add missing parent_map for two clocks If a clk_rcg2 has a parent, it should also have parent_map defined, otherwise we'll get a NULL pointer dereference when calling clk_set_rate like the following: [ 3.388105] Call trace: [ 3.390664] qcom_find_src_index+0x3c/0x70 (P) [ 3.395301] qcom_find_src_index+0x1c/0x70 (L) [ 3.399934] _freq_tbl_determine_rate+0x48/0x100 [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28 [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4 [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300 [ 3.455886] clk_set_rate+0x38/0x14c Add the parent_map property for two clocks where it's missing and also un-inline the parent_data as well to keep the matching parent_map and parent_data together. | 5.5 |
2025-03-06 | CVE-2024-58080 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: clk: qcom: dispcc-sm6350: Add missing parent_map for a clock If a clk_rcg2 has a parent, it should also have parent_map defined, otherwise we'll get a NULL pointer dereference when calling clk_set_rate like the following: [ 3.388105] Call trace: [ 3.390664] qcom_find_src_index+0x3c/0x70 (P) [ 3.395301] qcom_find_src_index+0x1c/0x70 (L) [ 3.399934] _freq_tbl_determine_rate+0x48/0x100 [ 3.404753] clk_rcg2_determine_rate+0x1c/0x28 [ 3.409387] clk_core_determine_round_nolock+0x58/0xe4 [ 3.421414] clk_core_round_rate_nolock+0x48/0xfc [ 3.432974] clk_core_round_rate_nolock+0xd0/0xfc [ 3.444483] clk_core_set_rate_nolock+0x8c/0x300 [ 3.455886] clk_set_rate+0x38/0x14c Add the parent_map property for the clock where it's missing and also un-inline the parent_data as well to keep the matching parent_map and parent_data together. | 5.5 |
2025-03-06 | CVE-2024-58081 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: clk: mmp2: call pm_genpd_init() only after genpd.name is set Setting the genpd's struct device's name with dev_set_name() is happening within pm_genpd_init(). | 5.5 |
2025-03-06 | CVE-2024-58084 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix missing read barrier in qcom_scm_get_tzmem_pool() Commit 2e4955167ec5 ("firmware: qcom: scm: Fix __scm and waitq completion variable initialization") introduced a write barrier in probe function to store global '__scm' variable. | 5.5 |
2025-03-06 | CVE-2025-21833 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE There is a WARN_ON_ONCE to catch an unlikely situation when domain_remove_dev_pasid can't find the `pasid`. | 5.5 |
2025-03-06 | CVE-2024-58052 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table The function atomctrl_get_smc_sclk_range_table() does not check the return value of smu_atom_get_data_table(). | 5.5 |
2025-03-06 | CVE-2024-58058 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ubifs: skip dumping tnc tree when zroot is null Clearing slab cache will free all znode in memory and make c->zroot.znode = NULL, then dumping tnc tree will access c->zroot.znode which cause null pointer dereference. | 5.5 |
2025-03-06 | CVE-2024-58059 | Linux | Improper Locking vulnerability in Linux Kernel 6.13/6.13.1 In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix deadlock during uvc_probe If uvc_probe() fails, it can end up calling uvc_status_unregister() before uvc_status_init() is called. Fix this by checking if dev->status is NULL or not in uvc_status_unregister(). | 5.5 |
2025-03-06 | CVE-2024-58062 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: avoid NULL pointer dereference When iterating over the links of a vif, we need to make sure that the pointer is valid (in other words - that the link exists) before dereferncing it. Use for_each_vif_active_link that also does the check. | 5.5 |
2025-03-06 | CVE-2024-58063 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: fix memory leaks and invalid access at probe error path Deinitialize at reverse order when probe fails. When init_sw_vars fails, rtl_deinit_core should not be called, specially now that it destroys the rtl_wq workqueue. And call rtl_pci_deinit and deinit_sw_vars, otherwise, memory will be leaked. Remove pci_set_drvdata call as it will already be cleaned up by the core driver code and could lead to memory leaks too. | 5.5 |
2025-03-06 | CVE-2024-58064 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: tests: Fix potential NULL dereference in test_cfg80211_parse_colocated_ap() kunit_kzalloc() may return NULL, dereferencing it without NULL check may lead to NULL dereference. Add a NULL check for ies. | 5.5 |
2025-03-06 | CVE-2024-58065 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1 In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() check The devm_kzalloc() function returns NULL on error, not error pointers. Fix the check. | 5.5 |
2025-03-06 | CVE-2024-58066 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1 In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() check The devm_kzalloc() function doesn't return error pointers, it returns NULL on error. | 5.5 |
2025-03-06 | CVE-2024-58067 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1 In the Linux kernel, the following vulnerability has been resolved: clk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() check The devm_kzalloc() function returns NULL on error, not error pointers. Update the check to match. | 5.5 |
2025-03-06 | CVE-2024-58068 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized If a driver calls dev_pm_opp_find_bw_ceil/floor() the retrieve bandwidth from the OPP table but the bandwidth table was not created because the interconnect properties were missing in the OPP consumer node, the kernel will crash with: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004 ... pc : _read_bw+0x8/0x10 lr : _opp_table_find_key+0x9c/0x174 ... Call trace: _read_bw+0x8/0x10 (P) _opp_table_find_key+0x9c/0x174 (L) _find_key+0x98/0x168 dev_pm_opp_find_bw_ceil+0x50/0x88 ... In order to fix the crash, create an assert function to check if the bandwidth table was created before trying to get a bandwidth with _read_bw(). | 5.5 |
2025-03-06 | CVE-2024-58070 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT In PREEMPT_RT, kmalloc(GFP_ATOMIC) is still not safe in non preemptible context. | 5.5 |
2025-03-06 | CVE-2024-58071 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: team: prevent adding a device which is already a team device lower Prevent adding a device which is already a team device lower, e.g. | 5.5 |
2025-03-06 | CVE-2024-58073 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel 6.13/6.13.1 In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: check dpu_plane_atomic_print_state() for valid sspp Similar to the r_pipe sspp protect, add a check to protect the pipe state prints to avoid NULL ptr dereference for cases when the state is dumped without a corresponding atomic_check() where the pipe->sspp is assigned. Patchwork: https://patchwork.freedesktop.org/patch/628404/ | 5.5 |
2025-03-06 | CVE-2025-1672 | The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. | 5.5 | |
2025-03-04 | CVE-2024-58043 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2024-58044 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability. | 5.5 |
2025-03-04 | CVE-2024-58046 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2024-58047 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2024-58049 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2024-58050 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2025-27521 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2025-03-04 | CVE-2025-20011 | Openatom | Memory Leak vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory. | 5.5 |
2025-03-04 | CVE-2025-20021 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-20042 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-21089 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-21097 | Openatom | NULL Pointer Dereference vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference. | 5.5 |
2025-03-04 | CVE-2025-21098 | Openatom | Insecure Storage of Sensitive Information vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check. | 5.5 |
2025-03-04 | CVE-2025-22443 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-22837 | Openatom | NULL Pointer Dereference vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference. | 5.5 |
2025-03-04 | CVE-2025-22841 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-22847 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-04 | CVE-2025-22897 | Openatom | Classic Buffer Overflow vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow. | 5.5 |
2025-03-04 | CVE-2025-23234 | Openatom | Classic Buffer Overflow vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow. | 5.5 |
2025-03-04 | CVE-2025-23418 | Openatom | Out-of-bounds Read vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read. | 5.5 |
2025-03-03 | CVE-2024-45778 | GNU Redhat | Integer Overflow or Wraparound vulnerability in multiple products A stack overflow flaw was found when reading a BFS file system. | 5.5 |
2025-03-03 | CVE-2024-43051 | Qualcomm | Improper Authorization vulnerability in Qualcomm products Information disclosure while deriving keys for a session for any Widevine use case. | 5.5 |
2025-03-03 | CVE-2024-53025 | Qualcomm | Integer Overflow or Wraparound vulnerability in Qualcomm products Transient DOS can occur while processing UCI command. | 5.5 |
2025-03-09 | CVE-2025-2130 | Openxe | Cross-site Scripting vulnerability in Openxe A vulnerability was found in OpenXE up to 1.12. | 5.4 |
2025-03-08 | CVE-2024-13649 | Wpxpro | Cross-site Scripting vulnerability in Wpxpro Xpro Addons for Elementor The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2024-13675 | Funnelkit | Cross-site Scripting vulnerability in Funnelkit Slingblocks The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2025-1664 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2025-1324 | Plechevandrey | Cross-site Scripting vulnerability in Plechevandrey Wp-Recall The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-03-08 | CVE-2025-1783 | Tiptoppress | Cross-site Scripting vulnerability in Tiptoppress Gallery Styles The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2024-13816 | Coderevolution | Missing Authorization vulnerability in Coderevolution Aiomatic The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 2.3.6. | 5.4 |
2025-03-08 | CVE-2025-1287 | Posimyth | Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2024-12119 | Fooplugins | Cross-site Scripting vulnerability in Fooplugins Foogallery The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-08 | CVE-2025-1261 | Hasthemes | Cross-site Scripting vulnerability in Hasthemes HT Mega The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-03-07 | CVE-2025-26643 | Microsoft | Unspecified vulnerability in Microsoft Edge Chromium The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 5.4 |
2025-03-05 | CVE-2025-20208 | Cisco | Cross-site Scripting vulnerability in Cisco Telepresence Management Suite 15.13.6 A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. | 5.4 |
2025-03-05 | CVE-2024-12650 | An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memory area. | 5.4 | |
2025-03-04 | CVE-2025-0370 | Vanokhin | Cross-site Scripting vulnerability in Vanokhin Shortcodes Ultimate The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘src’ parameter in all versions up to, and including, 7.3.3 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-04 | CVE-2024-9618 | Master Addons | Cross-site Scripting vulnerability in Master-Addons Master Addons The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-03-04 | CVE-2025-0433 | Master Addons | Cross-site Scripting vulnerability in Master-Addons Master Addons The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-04 | CVE-2025-0512 | Wpsc Plugin | Cross-site Scripting vulnerability in Wpsc-Plugin Structured Content The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-03-03 | CVE-2024-55064 | Easyvirt | Unspecified vulnerability in Easyvirt DC Netscope Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter. | 5.4 |
2025-03-03 | CVE-2024-54179 | IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. | 5.4 | |
2025-03-03 | CVE-2024-8186 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.9 before 17.9.1. | 5.4 |
2025-03-07 | CVE-2023-43052 | IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. | 5.3 | |
2025-03-07 | CVE-2024-12610 | The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. | 5.3 | |
2025-03-07 | CVE-2024-12611 | The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. | 5.3 | |
2025-03-06 | CVE-2025-2029 | A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. | 5.3 | |
2025-03-05 | CVE-2024-11153 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the WordPress core search feature. | 5.3 | |
2025-03-05 | CVE-2024-13423 | The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. | 5.3 | |
2025-03-05 | CVE-2024-8682 | The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. | 5.3 | |
2025-03-04 | CVE-2025-1925 | A vulnerability classified as problematic was found in Open5GS up to 2.7.2. | 5.3 | |
2025-03-04 | CVE-2025-20024 | Openatom | Integer Overflow or Wraparound vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. | 5.3 |
2025-03-04 | CVE-2025-20081 | Openatom | Use After Free vulnerability in Openatom Openharmony in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. | 5.3 |
2025-03-04 | CVE-2025-27221 | TAL | Unspecified vulnerability in TAL URL In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host. | 5.3 |
2025-03-03 | CVE-2025-24023 | Dpgaspar | Response Discrepancy Information Exposure vulnerability in Dpgaspar Flask-Appbuilder Flask-AppBuilder is an application development framework. | 5.3 |
2025-03-03 | CVE-2024-38426 | Qualcomm | Improper Authentication vulnerability in Qualcomm products While processing the authentication message in UE, improper authentication may lead to information disclosure. | 5.3 |
2025-03-08 | CVE-2024-13844 | Wpexperts | SQL Injection vulnerability in Wpexperts Post Smtp The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-03-03 | CVE-2024-51958 | Esri | Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1 There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. | 4.9 |
2025-03-03 | CVE-2024-51966 | Esri | Path Traversal vulnerability in Esri Arcgis Server 10.9.1/11.1 There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. | 4.9 |
2025-03-03 | CVE-2025-27274 | Axelkeller | Path Traversal: '.../...//' vulnerability in Axelkeller GPX Viewer Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal. | 4.9 |
2025-03-09 | CVE-2025-2131 | Xunruicms | Code Injection vulnerability in Xunruicms A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. | 4.8 |
2025-03-04 | CVE-2025-1892 | Qzw1210 | Unspecified vulnerability in Qzw1210 Shishuocms 1.1 A vulnerability was found in shishuocms 1.1. | 4.8 |
2025-03-03 | CVE-2024-10904 | Esri | Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1 There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | 4.8 |
2025-03-03 | CVE-2024-51942 | Esri | Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1 There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | 4.8 |
2025-03-03 | CVE-2024-51944 | Esri | Cross-site Scripting vulnerability in Esri Arcgis Server 10.9.1/11.1 There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | 4.8 |
2025-03-07 | CVE-2025-2054 | A vulnerability was found in code-projects Blood Bank Management System 1.0. | 4.7 | |
2025-03-06 | CVE-2025-2043 | A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. | 4.7 | |
2025-03-06 | CVE-2025-2044 | A vulnerability was found in code-projects Blood Bank Management System 1.0. | 4.7 | |
2025-03-06 | CVE-2025-2039 | A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. | 4.7 | |
2025-03-06 | CVE-2025-0877 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS).This issue affects Reservation Management System: before 4.2.3. | 4.7 | |
2025-03-04 | CVE-2024-58045 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability. | 4.7 |
2025-03-04 | CVE-2024-58048 | Huawei | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability. | 4.7 |
2025-03-09 | CVE-2025-2125 | Assaabloy | Resource Injection vulnerability in Assaabloy Control ID Rhid 25.2.25.0 A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. | 4.3 |
2025-03-09 | CVE-2025-2116 | A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as problematic. | 4.3 | |
2025-03-08 | CVE-2024-10326 | Rometheme | Missing Authorization vulnerability in Rometheme Romethemekit for Elementor The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. | 4.3 |
2025-03-08 | CVE-2025-1322 | Plechevandrey | Information Exposure vulnerability in Plechevandrey Wp-Recall The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included. | 4.3 |
2025-03-08 | CVE-2024-10321 | Themesgrove | Information Exposure vulnerability in Themesgrove All-In-One Addons for Elementor The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/advanced-tab/template/view.php. | 4.3 |
2025-03-08 | CVE-2024-12114 | Fooplugins | Authorization Bypass Through User-Controlled Key vulnerability in Fooplugins Foogallery The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). | 4.3 |
2025-03-08 | CVE-2025-1481 | Jozoor | Missing Authorization vulnerability in Jozoor Shortcode Cleaner Lite The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1.0.9. | 4.3 |
2025-03-07 | CVE-2024-13552 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled key. | 4.3 | |
2025-03-07 | CVE-2024-13635 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. | 4.3 | |
2025-03-07 | CVE-2025-2061 | A vulnerability was found in code-projects Online Ticket Reservation System 1.0. | 4.3 | |
2025-03-07 | CVE-2024-13526 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. | 4.3 | |
2025-03-07 | CVE-2025-0748 | The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. | 4.3 | |
2025-03-06 | CVE-2025-2042 | A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. | 4.3 | |
2025-03-06 | CVE-2025-1383 | Podlove | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podcast Publisher The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. | 4.3 |
2025-03-06 | CVE-2025-1666 | The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. | 4.3 | |
2025-03-05 | CVE-2025-1463 | The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. | 4.3 | |
2025-03-05 | CVE-2024-13747 | The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'template_delete_saved' function in all versions up to, and including, 3.0.34. | 4.3 | |
2025-03-05 | CVE-2024-13810 | The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'zass_import_zass' AJAX actions in all versions up to, and including, 3.9.9.10. | 4.3 | |
2025-03-05 | CVE-2024-13811 | The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. | 4.3 | |
2025-03-05 | CVE-2025-0990 | The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.4. | 4.3 | |
2025-03-04 | CVE-2024-13682 | Wpswings | Cross-Site Request Forgery (CSRF) vulnerability in Wpswings Wallet System for Woocommerce The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. | 4.3 |
2025-03-04 | CVE-2024-13724 | Wpswings | Improper Authorization vulnerability in Wpswings Wallet System for Woocommerce The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. | 4.3 |
2025-03-04 | CVE-2024-13686 | The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. | 4.3 | |
2025-03-03 | CVE-2025-1881 | I Drive | Incorrect Privilege Assignment vulnerability in I-Drive I11 Firmware and I12 Firmware A vulnerability was found in i-Drive i11 and i12 up to 20250227. | 4.3 |
2025-03-03 | CVE-2025-1880 | I Drive | Authentication Bypass by Primary Weakness vulnerability in I-Drive I11 Firmware and I12 Firmware A vulnerability was found in i-Drive i11 and i12 up to 20250227. | 4.3 |
2025-03-03 | CVE-2025-1842 | A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. | 4.3 |