2025-03-19 | CVE-2024-12136 | | Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: through 19.03.2025. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. | 6.9 |
2025-03-18 | CVE-2025-0694 | | Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access. | 6.6 |
2025-03-23 | CVE-2025-29806 | Microsoft | Code Injection vulnerability in Microsoft Edge Chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 6.5 |
2025-03-22 | CVE-2025-1311 | | The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-03-22 | CVE-2025-0723 | Metagauss | SQL Injection vulnerability in Metagauss Profilegrid The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-03-21 | CVE-2025-30179 | Mattermost | Incorrect Authorization vulnerability in Mattermost Server Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries. | 6.5 |
2025-03-21 | CVE-2025-30343 | Openslides | Path Traversal vulnerability in Openslides 3.2 A directory traversal issue was discovered in OpenSlides before 4.2.5. | 6.5 |
2025-03-20 | CVE-2025-1496 | | Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227. | 6.5 |
2025-03-20 | CVE-2024-13922 | Webtoffee | External Control of File Name or Path vulnerability in Webtoffee Order Export & Order Import for Woocommerce The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. | 6.5 |
2025-03-20 | CVE-2024-13923 | Webtoffee | Server-Side Request Forgery (SSRF) vulnerability in Webtoffee Order Export & Order Import for Woocommerce The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. | 6.5 |
2025-03-20 | CVE-2024-11300 | Lunary | Unspecified vulnerability in Lunary In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. | 6.5 |
2025-03-20 | CVE-2024-8736 | Lollms | Cross-Site Request Forgery (CSRF) vulnerability in Lollms web UI 12 A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). | 6.5 |
2025-03-20 | CVE-2024-9612 | Onyx | Unspecified vulnerability in Onyx 0.3.94 In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. | 6.5 |
2025-03-23 | CVE-2018-25109 | | A vulnerability has been found in Nintendo Animal Crossing, Doubutsu no Mori+ and Doubutsu no Mori e+ 1.00/1.01 on GameCube and classified as critical. | 6.4 |
2025-03-22 | CVE-2025-2577 | | The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. | 6.4 |
2025-03-22 | CVE-2024-13856 | | The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.10 via the make_builder_ajax_subscribe() function. | 6.4 |
2025-03-20 | CVE-2025-2108 | | The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Site Title’ widget's 'title_tag' and 'html_tag' parameters in all versions up to, and including, 1.4.6.8 due to insufficient input sanitization and output escaping. | 6.4 |
2025-03-23 | CVE-2025-2671 | | A vulnerability was found in Yue Lao Blind Box ???? up to 4.0. | 6.3 |
2025-03-23 | CVE-2025-2662 | | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. | 6.3 |
2025-03-21 | CVE-2025-2608 | | A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. | 6.3 |
2025-03-21 | CVE-2025-2601 | | A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. | 6.3 |
2025-03-21 | CVE-2025-2602 | | A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. | 6.3 |
2025-03-21 | CVE-2025-2592 | | A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. | 6.3 |
2025-03-21 | CVE-2025-2587 | Jinher | SQL Injection vulnerability in Jinher OA C6 1.0 A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. | 6.3 |
2025-03-18 | CVE-2025-2471 | | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. | 6.3 |
2025-03-17 | CVE-2025-2373 | | A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. | 6.3 |
2025-03-17 | CVE-2025-2374 | | A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. | 6.3 |
2025-03-17 | CVE-2025-2367 | | A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical. | 6.3 |
2025-03-17 | CVE-2025-2368 | | A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. | 6.3 |
2025-03-17 | CVE-2025-2365 | | A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. | 6.3 |
2025-03-17 | CVE-2025-2363 | | A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. | 6.3 |
2025-03-17 | CVE-2025-2358 | | A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. | 6.3 |
2025-03-17 | CVE-2025-2357 | | A vulnerability was found in DCMTK 3.6.9. | 6.3 |
2025-03-23 | CVE-2025-2650 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul Medical Card Generation System 1.0 A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. | 6.1 |
2025-03-23 | CVE-2025-2645 | Phpgurukul | Cross-site Scripting vulnerability in PHPgurukul ART Gallery Management System 1.0 A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. | 6.1 |
2025-03-22 | CVE-2025-2479 | | The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. | 6.1 |
2025-03-22 | CVE-2025-2482 | | The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. | 6.1 |
2025-03-22 | CVE-2025-2484 | | The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_id' parameters in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. | 6.1 |
2025-03-22 | CVE-2024-13739 | Tribulant | Cross-site Scripting vulnerability in Tribulant Newsletters The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping. | 6.1 |
2025-03-21 | CVE-2025-2609 | Magnussolution | Cross-site Scripting vulnerability in Magnussolution Magnusbilling Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0. | 6.1 |
2025-03-21 | CVE-2025-2597 | Itechno | Cross-site Scripting vulnerability in Itechno Itium 6050 Firmware 5.5.5.2B3526 Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. | 6.1 |
2025-03-21 | CVE-2025-2583 | Simplemachines | Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1.4 A vulnerability was found in SimpleMachines SMF 2.1.4. | 6.1 |
2025-03-21 | CVE-2025-30342 | Openslides | Cross-site Scripting vulnerability in Openslides 3.2 An XSS issue was discovered in OpenSlides before 4.2.5. | 6.1 |
2025-03-20 | CVE-2024-10727 | Phpipam | Unspecified vulnerability in PHPipam A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. | 6.1 |
2025-03-20 | CVE-2024-8021 | Gradio Project | Unspecified vulnerability in Gradio Project Gradio An open redirect vulnerability exists in the latest version of gradio-app/gradio. | 6.1 |
2025-03-20 | CVE-2024-8101 | Aimstack | Unspecified vulnerability in Aimstack AIM 3.23.0 A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. | 6.1 |
2025-03-20 | CVE-2024-8556 | Modelscope | Unspecified vulnerability in Modelscope Agentscope A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. | 6.1 |
2025-03-20 | CVE-2024-9311 | Hliu | Cross-Site Request Forgery (CSRF) vulnerability in Hliu Large Language and Vision Assistant 1.2.0 A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. | 6.1 |
2025-03-20 | CVE-2024-9900 | Mudler | Cross-site Scripting vulnerability in Mudler Localai 2.21.1 mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. | 6.1 |
2025-03-19 | CVE-2024-55009 | Datax | Cross-site Scripting vulnerability in Datax Autobib A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter. | 6.1 |
2025-03-20 | CVE-2024-12910 | Llamaindex | Unspecified vulnerability in Llamaindex A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. | 5.9 |
2025-03-20 | CVE-2025-2557 | | A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. | 5.5 |
2025-03-20 | CVE-2025-1474 | Lfprojects | Weak Password Requirements vulnerability in Lfprojects Mlflow In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. | 5.5 |
2025-03-22 | CVE-2025-2623 | Westboy | Cross-site Scripting vulnerability in Westboy Cicadascms 1.0 A vulnerability was found in westboy CicadasCMS 1.0. | 5.4 |
2025-03-21 | CVE-2025-2610 | Magnussolution | Cross-site Scripting vulnerability in Magnussolution Magnusbilling Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. | 5.4 |
2025-03-21 | CVE-2025-2590 | Code Projects | Code Injection vulnerability in Code-Projects Human Resource Management 1.0.1 A vulnerability was found in code-projects Human Resource Management System 1.0.1. | 5.4 |
2025-03-21 | CVE-2025-2582 | Simplemachines | Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1.4 A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. | 5.4 |
2025-03-21 | CVE-2024-50053 | Zohocorp | Cross-site Scripting vulnerability in Zohocorp products Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature. | 5.4 |
2025-03-20 | CVE-2025-1802 | Hasthemes | Cross-site Scripting vulnerability in Hasthemes HT Mega The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. | 5.4 |
2025-03-20 | CVE-2024-10721 | Phpipam | Unspecified vulnerability in PHPipam 1.5.2 A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. | 5.4 |
2025-03-20 | CVE-2024-12871 | Infiniflow | Unspecified vulnerability in Infiniflow Ragflow 0.12.0 An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. | 5.4 |
2025-03-20 | CVE-2024-8400 | Gaizhenbiao | Unspecified vulnerability in Gaizhenbiao Chuanhuchatgpt A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. | 5.4 |
2025-03-20 | CVE-2025-0281 | Lunary | Cross-site Scripting vulnerability in Lunary A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. | 5.4 |
2025-03-19 | CVE-2024-53967 | | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. | 5.4 |
2025-03-19 | CVE-2024-53968 | | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. | 5.4 |
2025-03-19 | CVE-2024-53969 | | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. | 5.4 |
2025-03-19 | CVE-2024-53970 | | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. | 5.4 |
2025-03-17 | CVE-2025-26393 | | SolarWinds Service Desk is affected by a broken access control vulnerability. | 5.4 |
2025-03-23 | CVE-2025-2651 | | A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. | 5.3 |
2025-03-23 | CVE-2025-2639 | Jizhicms | Unspecified vulnerability in Jizhicms A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. | 5.3 |
2025-03-23 | CVE-2025-2638 | Jizhicms | Unspecified vulnerability in Jizhicms A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. | 5.3 |
2025-03-23 | CVE-2025-2637 | Jizhicms | Unspecified vulnerability in Jizhicms A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. | 5.3 |
2025-03-22 | CVE-2025-2331 | | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function. | 5.3 |
2025-03-22 | CVE-2024-13666 | | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. | 5.3 |
2025-03-21 | CVE-2025-30348 | QT | Algorithmic Complexity vulnerability in QT encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data). | 5.3 |
2025-03-20 | CVE-2024-13558 | Neahplugins | Authorization Bypass Through User-Controlled Key vulnerability in Neahplugins NP Quote Request for Woocommerce The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. | 5.3 |
2025-03-20 | CVE-2024-6838 | Lfprojects | Unspecified vulnerability in Lfprojects Mlflow 2.13.2 In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. | 5.3 |
2025-03-20 | CVE-2025-1766 | | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24. | 5.3 |
2025-03-19 | CVE-2025-2290 | | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. | 5.3 |
2025-03-18 | CVE-2024-41975 | | An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs. | 5.3 |
2025-03-22 | CVE-2025-2625 | Westboy | SQL Injection vulnerability in Westboy Cicadascms 1.0 A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. | 4.9 |
2025-03-22 | CVE-2025-1973 | | The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. | 4.9 |
2025-03-22 | CVE-2025-2478 | | The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-03-20 | CVE-2024-13920 | Webtoffee | Path Traversal vulnerability in Webtoffee Order Export & Order Import for Woocommerce The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. | 4.9 |
2025-03-19 | CVE-2025-2511 | | The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-03-18 | CVE-2025-2487 | | A flaw was found in the 389-ds-base LDAP Server. | 4.9 |
2025-03-21 | CVE-2025-30346 | Varnish Software Varnish Cache Project | HTTP Request Smuggling vulnerability in multiple products Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | 4.8 |
2025-03-23 | CVE-2025-2664 | | A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical. | 4.7 |
2025-03-22 | CVE-2025-2477 | | The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. | 4.7 |
2025-03-19 | CVE-2024-45644 | | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment. | 4.7 |
2025-03-17 | CVE-2025-2392 | | A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. | 4.7 |
2025-03-17 | CVE-2025-2389 | | A vulnerability was found in code-projects Blood Bank Management System 1.0. | 4.7 |
2025-03-23 | CVE-2025-2653 | | A vulnerability was found in FoxCMS 1.25 and classified as problematic. | 4.3 |
2025-03-22 | CVE-2024-13768 | | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. | 4.3 |
2025-03-22 | CVE-2025-0807 | | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. | 4.3 |
2025-03-22 | CVE-2025-1408 | Metagauss | Missing Authorization vulnerability in Metagauss Profilegrid The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. | 4.3 |
2025-03-22 | CVE-2024-13737 | Stylemixthemes | Missing Authorization vulnerability in Stylemixthemes Motors - CAR Dealer, Classifieds & Listing The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. | 4.3 |
2025-03-21 | CVE-2025-2591 | | A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. | 4.3 |
2025-03-21 | CVE-2025-24920 | Mattermost | Incorrect Authorization vulnerability in Mattermost Server Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels | 4.3 |
2025-03-21 | CVE-2025-27933 | Mattermost | Incorrect Authorization vulnerability in Mattermost Server Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public | 4.3 |
2025-03-20 | CVE-2025-2553 | | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2025-2556 | | A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. | 4.3 |
2025-03-20 | CVE-2025-2549 | | A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. | 4.3 |
2025-03-20 | CVE-2025-2550 | | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. | 4.3 |
2025-03-20 | CVE-2025-2551 | | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2025-2552 | | A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2025-2547 | | A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2025-2548 | | A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2025-2546 | | A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. | 4.3 |
2025-03-20 | CVE-2024-12869 | Infiniflow | Unspecified vulnerability in Infiniflow Ragflow 0.12.0 In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. | 4.3 |
2025-03-20 | CVE-2024-13060 | Mintplexlabs | Unspecified vulnerability in Mintplexlabs Anythingllm Docker A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. | 4.3 |
2025-03-20 | CVE-2025-1314 | | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. | 4.3 |
2025-03-19 | CVE-2024-7631 | | A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. | 4.3 |
2025-03-19 | CVE-2024-25132 | | A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. | 4.3 |
2025-03-17 | CVE-2025-2354 | | A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. | 4.3 |
2025-03-21 | CVE-2025-30345 | Openslides | Cross-site Scripting vulnerability in Openslides 3.2 An issue was discovered in OpenSlides before 4.2.5. | 4.1 |
2025-03-18 | CVE-2024-49822 | | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). | 4.1 |