Weekly Vulnerabilities Reports > March 17 to 23, 2025

Overview

270 new vulnerabilities reported during this period, including 49 critical vulnerabilities and 88 high severity vulnerabilities. This weekly summary report vulnerabilities in 78 products from 64 vendors including Phpgurukul, Mattermost, Ollama, Openslides, and Webtoffee. Vulnerabilities are notably categorized as "Injection", "SQL Injection", "Cross-site Scripting", "Code Injection", and "Incorrect Privilege Assignment".

  • 250 reported vulnerabilities are remotely exploitables.
  • 79 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 168 reported vulnerabilities are exploitable by an anonymous user.
  • Phpgurukul has the most reported vulnerabilities, with 15 reported vulnerabilities.
  • Phpgurukul has the most reported critical vulnerabilities, with 13 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

49 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-18 CVE-2024-56346 IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
10.0
2025-03-23 CVE-2025-2654 Oretnom23 Unspecified vulnerability in Oretnom23 AC Repair and Services System 1.0

A vulnerability was found in SourceCodester AC Repair and Services System 1.0.

9.8
2025-03-23 CVE-2025-2648 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-23 CVE-2025-2649 Phpgurukul SQL Injection vulnerability in PHPgurukul Doctor Appointment Management System 1.0.0

A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0.

9.8
2025-03-23 CVE-2025-2647 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-23 CVE-2025-2646 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-23 CVE-2025-2643 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical.

9.8
2025-03-23 CVE-2025-2644 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical.

9.8
2025-03-23 CVE-2025-2642 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-23 CVE-2025-1446 Podsfoundation SQL Injection vulnerability in Podsfoundation Pods

The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

9.8
2025-03-23 CVE-2025-2641 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-23 CVE-2025-2640 Phpgurukul SQL Injection vulnerability in PHPgurukul Doctor Appointment Management System 1.0.0

A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical.

9.8
2025-03-22 CVE-2025-2628 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.1

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1.

9.8
2025-03-22 CVE-2025-2626 Mayurik SQL Injection vulnerability in Mayurik Advocate Office Management System 1.0

A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.

9.8
2025-03-22 CVE-2025-2627 Phpgurukul SQL Injection vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0.

9.8
2025-03-22 CVE-2025-2621 Dlink Out-of-bounds Write vulnerability in Dlink Dap-1620 Firmware 1.03

A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical.

9.8
2025-03-22 CVE-2025-30472 Corosync Out-of-bounds Write vulnerability in Corosync

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

9.8
2025-03-21 CVE-2025-2589 Code Projects Missing Authorization vulnerability in Code-Projects Human Resource Management 1.0.1

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical.

9.8
2025-03-21 CVE-2025-26336 Dell Stack-based Buffer Overflow vulnerability in Dell products

Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability.

9.8
2025-03-20 CVE-2024-12450 Infiniflow Server-Side Request Forgery (SSRF) vulnerability in Infiniflow Ragflow 0.12.0

In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities.

9.8
2025-03-20 CVE-2024-7773 Ollama Unspecified vulnerability in Ollama 0.1.37

A vulnerability in ollama/ollama version 0.1.37 allows for remote code execution (RCE) due to improper input validation in the handling of zip files.

9.8
2025-03-20 CVE-2024-8156 Agpt Unspecified vulnerability in Agpt Autogpt

A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt.

9.8
2025-03-20 CVE-2024-8487 Modelscope Unspecified vulnerability in Modelscope Agentscope 0.0.4

A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4.

9.8
2025-03-20 CVE-2024-8898 Lollms Unspecified vulnerability in Lollms web UI 12

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry).

9.8
2025-03-20 CVE-2024-8953 Composio Improper Control of Dynamically-Managed Code Resources vulnerability in Composio 0.4.3

In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations.

9.8
2025-03-20 CVE-2024-8958 Composio Unspecified vulnerability in Composio 0.4.3

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions.

9.8
2025-03-20 CVE-2025-0655 MAN OS Command Injection vulnerability in MAN D-Tale 3.15.1

A vulnerability in man-group/dtale versions 3.15.1 allows an attacker to override global state settings to enable the `enable_custom_filters` feature, which is typically restricted to trusted environments.

9.8
2025-03-20 CVE-2024-12016 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.
9.8
2025-03-20 CVE-2025-2505 The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter.
9.8
2025-03-19 CVE-2024-13442 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0.
9.8
2025-03-19 CVE-2025-2512 The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1.
9.8
2025-03-19 CVE-2024-13790 The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter.
9.8
2025-03-19 CVE-2024-13410 The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versions up to, and including 3.9.0, respectively, via deserialization of untrusted input in the 'ajax_handler' function.
9.8
2025-03-19 CVE-2024-12922 The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4.
9.8
2025-03-18 CVE-2024-8997 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection.This issue affects EVC04 Configuration Interface: through 18.03.2025.
9.8
2025-03-17 CVE-2025-2385 Code Projects SQL Injection vulnerability in Code-Projects Modern BAG 1.0

A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical.

9.8
2025-03-17 CVE-2025-2386 Phpgurukul SQL Injection vulnerability in PHPgurukul Local Services Search Engine Management System 1.0

A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical.

9.8
2025-03-17 CVE-2025-2383 Phpgurukul SQL Injection vulnerability in PHPgurukul Doctor Appointment Management System 1.0.0

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0.

9.8
2025-03-17 CVE-2025-2369 A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316.
9.8
2025-03-17 CVE-2025-2370 A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316.
9.8
2025-03-17 CVE-2025-2395 The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
9.8
2025-03-18 CVE-2024-56347 IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
9.6
2025-03-21 CVE-2025-29814 Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
9.3
2025-03-23 CVE-2025-2691 Nossrf Project Unspecified vulnerability in Nossrf Project Nossrf

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.

9.1
2025-03-20 CVE-2024-4990 Yiiframework Unspecified vulnerability in Yiiframework YII 2.0.48

In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration.

9.1
2025-03-20 CVE-2024-7776 Onnx Unspecified vulnerability in Onnx

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files.

9.1
2025-03-20 CVE-2024-8769 Aimstack Path Traversal vulnerability in Aimstack AIM

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal.

9.1
2025-03-18 CVE-2024-23943 An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical function in the affected devices.
9.1
2025-03-20 CVE-2024-7053 Openwebui Unspecified vulnerability in Openwebui Open Webui 0.3.8

A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack.

9.0

88 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-22 CVE-2025-2622 Aizuda Unspecified vulnerability in Aizuda Snail-Job 1.4.0

A vulnerability was found in aizuda snail-job 1.4.0.

8.8
2025-03-22 CVE-2025-2303 The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function.
8.8
2025-03-22 CVE-2025-0724 Metagauss Deserialization of Untrusted Data vulnerability in Metagauss Profilegrid

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function.

8.8
2025-03-21 CVE-2025-25068 Mattermost Missing Authentication for Critical Function vulnerability in Mattermost Server

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.

8.8
2025-03-21 CVE-2025-25274 Mattermost Command Injection vulnerability in Mattermost Server

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.

8.8
2025-03-21 CVE-2025-2585 EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
8.8
2025-03-20 CVE-2025-23120 Veeam Unspecified vulnerability in Veeam Backup & Replication

A vulnerability allowing remote code execution (RCE) for domain users.

8.8
2025-03-20 CVE-2024-7806 Openwebui Unspecified vulnerability in Openwebui Open Webui

A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF).

8.8
2025-03-20 CVE-2024-8501 Modelscope Unspecified vulnerability in Modelscope Agentscope 0.0.4

An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4.

8.8
2025-03-20 CVE-2024-9920 Lollms Unrestricted Upload of File with Dangerous Type vulnerability in Lollms web UI 12

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more.

8.8
2025-03-20 CVE-2025-0185 Dify Code Injection vulnerability in Dify

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version.

8.8
2025-03-20 CVE-2025-1040 Agpt Unspecified vulnerability in Agpt Autogpt

AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE).

8.8
2025-03-20 CVE-2025-1770 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the 'style' parameter.
8.8
2025-03-19 CVE-2024-12920 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions in all versions up to, and including, 4.7.
8.8
2025-03-19 CVE-2024-13933 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.
8.8
2025-03-19 CVE-2024-12295 The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0.
8.8
2025-03-18 CVE-2024-12563 The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute.
8.8
2025-03-17 CVE-2025-2396 The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
8.8
2025-03-21 CVE-2025-29807 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
8.7
2025-03-19 CVE-2025-30154 Reviewdog Embedded Malicious Code vulnerability in Reviewdog products

reviewdog/action-setup is a GitHub action that installs reviewdog.

8.6
2025-03-19 CVE-2024-51459 IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
8.4
2025-03-20 CVE-2024-8053 Openwebui Missing Authentication for Critical Function vulnerability in Openwebui Open Webui 0.3.10

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service.

8.2
2025-03-17 CVE-2025-2241 A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM).
8.2
2025-03-20 CVE-2024-7767 Onyx Unspecified vulnerability in Onyx 0.3.94

An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94.

8.1
2025-03-20 CVE-2024-8026 Qanything Unspecified vulnerability in Qanything

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc.

8.1
2025-03-23 CVE-2025-29795 Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
7.8
2025-03-22 CVE-2025-1970 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via the validate_file() function.
7.6
2025-03-19 CVE-2024-12137 Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking.This issue affects ANKA JPD-00028: through 19.03.2025. NOTE: The vendor did not inform about the completion of the fixing process within the specified time.
7.6
2025-03-23 CVE-2025-2672 Fabianros Injection vulnerability in Fabianros Employees Payroll Management System 1.0

A vulnerability was found in code-projects Payroll Management System 1.0.

7.5
2025-03-23 CVE-2025-2652 Oretnom23 Unspecified vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic.

7.5
2025-03-22 CVE-2025-2624 Westboy SQL Injection vulnerability in Westboy Cicadascms 1.0

A vulnerability was found in westboy CicadasCMS 1.0.

7.5
2025-03-22 CVE-2025-2186 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-03-21 CVE-2025-30157 Envoyproxy Unspecified vulnerability in Envoyproxy Envoy

Envoy is a cloud-native high-performance edge/middle/service proxy.

7.5
2025-03-21 CVE-2024-13903 Quickjs NG Stack-based Buffer Overflow vulnerability in Quickjs-Ng Quickjs

A vulnerability was found in quickjs-ng QuickJS up to 0.8.0.

7.5
2025-03-21 CVE-2025-30347 Varnish Software Out-of-bounds Read vulnerability in Varnish-Software Varnish Enterprise 6.0.13

Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

7.5
2025-03-21 CVE-2025-2581 Xmedcon Project Integer Underflow (Wrap or Wraparound) vulnerability in Xmedcon Project Xmedcon 0.25.0

A vulnerability has been found in xmedcon 0.25.0 and classified as problematic.

7.5
2025-03-20 CVE-2025-2539 The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1.
7.5
2025-03-20 CVE-2024-11822 Dify Unspecified vulnerability in Dify 0.9.1

langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability.

7.5
2025-03-20 CVE-2024-12537 Openwebui Allocation of Resources Without Limits or Throttling vulnerability in Openwebui Open Webui 0.3.32

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint.

7.5
2025-03-20 CVE-2024-12779 Infiniflow Unspecified vulnerability in Infiniflow Ragflow 0.12.0

A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0.

7.5
2025-03-20 CVE-2024-7765 H2O Unspecified vulnerability in H2O 3.46.0.2

In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service.

7.5
2025-03-20 CVE-2024-8062 H2O Unspecified vulnerability in H2O 3.46.0

A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service.

7.5
2025-03-20 CVE-2024-8524 Modelscope Unspecified vulnerability in Modelscope Agentscope 0.0.4

A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4.

7.5
2025-03-20 CVE-2024-8952 Composio Unspecified vulnerability in Composio 0.4.2

A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint.

7.5
2025-03-20 CVE-2024-8966 Gradio Unspecified vulnerability in Gradio Video 0.10.2

A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack.

7.5
2025-03-20 CVE-2024-8998 Lunary Unspecified vulnerability in Lunary

A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845.

7.5
2025-03-20 CVE-2024-9606 Litellm Improper Output Neutralization for Logs vulnerability in Litellm

In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key.

7.5
2025-03-20 CVE-2025-0189 Aimstack Resource Exhaustion vulnerability in Aimstack AIM 3.25.0

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack.

7.5
2025-03-20 CVE-2025-0190 Aimstack Excessive Data Query Operations in a Large Data Table vulnerability in Aimstack AIM 3.25.0

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists.

7.5
2025-03-20 CVE-2025-0312 Ollama NULL Pointer Dereference vulnerability in Ollama

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference.

7.5
2025-03-20 CVE-2025-0313 Ollama Improper Validation of Array Index vulnerability in Ollama

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a GGUF model that can cause a denial of service (DoS) attack.

7.5
2025-03-20 CVE-2025-0315 Ollama Allocation of Resources Without Limits or Throttling vulnerability in Ollama

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it.

7.5
2025-03-20 CVE-2025-0317 Ollama Divide By Zero vulnerability in Ollama

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server.

7.5
2025-03-20 CVE-2025-0453 Lfprojects Unspecified vulnerability in Lfprojects Mlflow 2.17.2

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack.

7.5
2025-03-20 CVE-2025-1451 Lollms Resource Exhaustion vulnerability in Lollms web UI 13

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads.

7.5
2025-03-19 CVE-2024-13412 The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0.
7.5
2025-03-18 CVE-2025-1468 An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.
7.5
2025-03-17 CVE-2025-2419 Fabianros SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0.

7.5
2025-03-17 CVE-2025-2384 Fabianros SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0

A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0.

7.5
2025-03-21 CVE-2025-2584 Webassembly Heap-based Buffer Overflow vulnerability in Webassembly Wabt 1.0.36

A vulnerability was found in WebAssembly wabt 1.0.36.

7.4
2025-03-23 CVE-2025-2665 A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0.
7.3
2025-03-23 CVE-2025-2663 A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical.
7.3
2025-03-23 CVE-2025-2661 A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical.
7.3
2025-03-23 CVE-2025-2659 A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0.
7.3
2025-03-23 CVE-2025-2660 A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical.
7.3
2025-03-23 CVE-2025-2657 A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0.
7.3
2025-03-23 CVE-2025-2658 A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0.
7.3
2025-03-23 CVE-2025-2655 A vulnerability was found in SourceCodester AC Repair and Services System 1.0.
7.3
2025-03-23 CVE-2025-2656 A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1.
7.3
2025-03-18 CVE-2025-2262 The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3.
7.3
2025-03-18 CVE-2025-2472 A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical.
7.3
2025-03-18 CVE-2025-2473 A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical.
7.3
2025-03-17 CVE-2025-2391 A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0.
7.3
2025-03-17 CVE-2025-2387 A vulnerability was found in SourceCodester Online Food Ordering System 2.0.
7.3
2025-03-17 CVE-2025-2388 A vulnerability was found in Keytop ???????? 2.7.1.
7.3
2025-03-17 CVE-2025-2381 A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0.
7.3
2025-03-17 CVE-2025-2382 A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0.
7.3
2025-03-17 CVE-2025-2379 A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0.
7.3
2025-03-17 CVE-2025-2380 A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0.
7.3
2025-03-17 CVE-2025-2376 A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical.
7.3
2025-03-17 CVE-2025-2372 A vulnerability classified as critical has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
7.3
2025-03-17 CVE-2025-2362 A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0.
7.3
2025-03-17 CVE-2025-2359 A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207.
7.3
2025-03-17 CVE-2025-2360 A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207.
7.3
2025-03-17 CVE-2025-2353 A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2.
7.3
2025-03-22 CVE-2025-1971 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'form_data' parameter.
7.2
2025-03-20 CVE-2024-13921 Webtoffee Deserialization of Untrusted Data vulnerability in Webtoffee Order Export & Order Import for Woocommerce

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter.

7.2
2025-03-18 CVE-2024-23942 A local user may find a configuration file on the client workstation with unencrypted sensitive data.
7.1

117 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-19 CVE-2024-12136 Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass.This issue affects ANKA JPD-00028: through 19.03.2025. NOTE: The vendor did not inform about the completion of the fixing process within the specified time.
6.9
2025-03-18 CVE-2025-0694 Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
6.6
2025-03-23 CVE-2025-29806 Microsoft Code Injection vulnerability in Microsoft Edge Chromium

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
2025-03-22 CVE-2025-1311 The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in the update_delivery_status() function in all versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-03-22 CVE-2025-0723 Metagauss SQL Injection vulnerability in Metagauss Profilegrid

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-03-21 CVE-2025-30179 Mattermost Incorrect Authorization vulnerability in Mattermost Server

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.

6.5
2025-03-21 CVE-2025-30343 Openslides Path Traversal vulnerability in Openslides 3.2

A directory traversal issue was discovered in OpenSlides before 4.2.5.

6.5
2025-03-20 CVE-2025-1496 Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.
6.5
2025-03-20 CVE-2024-13922 Webtoffee External Control of File Name or Path vulnerability in Webtoffee Order Export & Order Import for Woocommerce

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0.

6.5
2025-03-20 CVE-2024-13923 Webtoffee Server-Side Request Forgery (SSRF) vulnerability in Webtoffee Order Export & Order Import for Woocommerce

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function.

6.5
2025-03-20 CVE-2024-11300 Lunary Unspecified vulnerability in Lunary

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user.

6.5
2025-03-20 CVE-2024-8736 Lollms Cross-Site Request Forgery (CSRF) vulnerability in Lollms web UI 12

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry).

6.5
2025-03-20 CVE-2024-9612 Onyx Unspecified vulnerability in Onyx 0.3.94

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page.

6.5
2025-03-23 CVE-2018-25109 A vulnerability has been found in Nintendo Animal Crossing, Doubutsu no Mori+ and Doubutsu no Mori e+ 1.00/1.01 on GameCube and classified as critical.
6.4
2025-03-22 CVE-2025-2577 The Bitspecter Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping.
6.4
2025-03-22 CVE-2024-13856 The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.10 via the make_builder_ajax_subscribe() function.
6.4
2025-03-20 CVE-2025-2108 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Site Title’ widget's 'title_tag' and 'html_tag' parameters in all versions up to, and including, 1.4.6.8 due to insufficient input sanitization and output escaping.
6.4
2025-03-23 CVE-2025-2671 A vulnerability was found in Yue Lao Blind Box ???? up to 4.0.
6.3
2025-03-23 CVE-2025-2662 A vulnerability was found in Project Worlds Online Time Table Generator 1.0.
6.3
2025-03-21 CVE-2025-2608 A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2.
6.3
2025-03-21 CVE-2025-2601 A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0.
6.3
2025-03-21 CVE-2025-2602 A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical.
6.3
2025-03-21 CVE-2025-2592 A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3.
6.3
2025-03-21 CVE-2025-2587 Jinher SQL Injection vulnerability in Jinher OA C6 1.0

A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0.

6.3
2025-03-18 CVE-2025-2471 A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0.
6.3
2025-03-17 CVE-2025-2373 A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
6.3
2025-03-17 CVE-2025-2374 A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
6.3
2025-03-17 CVE-2025-2367 A vulnerability has been found in Oiwtech OIW-2431APGN-HP 2.5.3-B20131128 and classified as critical.
6.3
2025-03-17 CVE-2025-2368 A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical.
6.3
2025-03-17 CVE-2025-2365 A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4.
6.3
2025-03-17 CVE-2025-2363 A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0.
6.3
2025-03-17 CVE-2025-2358 A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0.
6.3
2025-03-17 CVE-2025-2357 A vulnerability was found in DCMTK 3.6.9.
6.3
2025-03-23 CVE-2025-2650 Phpgurukul Cross-site Scripting vulnerability in PHPgurukul Medical Card Generation System 1.0

A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0.

6.1
2025-03-23 CVE-2025-2645 Phpgurukul Cross-site Scripting vulnerability in PHPgurukul ART Gallery Management System 1.0

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0.

6.1
2025-03-22 CVE-2025-2479 The Easy Custom Admin Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
6.1
2025-03-22 CVE-2025-2482 The Gotcha | Gesture-based Captcha plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menu' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping.
6.1
2025-03-22 CVE-2025-2484 The Multi Video Box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'video_id' and 'group_id' parameters in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping.
6.1
2025-03-22 CVE-2024-13739 Tribulant Cross-site Scripting vulnerability in Tribulant Newsletters

The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versions up to, and including, 4.9.9.7 due to insufficient input sanitization and output escaping.

6.1
2025-03-21 CVE-2025-2609 Magnussolution Cross-site Scripting vulnerability in Magnussolution Magnusbilling

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

6.1
2025-03-21 CVE-2025-2597 Itechno Cross-site Scripting vulnerability in Itechno Itium 6050 Firmware 5.5.5.2B3526

Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies.

6.1
2025-03-21 CVE-2025-2583 Simplemachines Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1.4

A vulnerability was found in SimpleMachines SMF 2.1.4.

6.1
2025-03-21 CVE-2025-30342 Openslides Cross-site Scripting vulnerability in Openslides 3.2

An XSS issue was discovered in OpenSlides before 4.2.5.

6.1
2025-03-20 CVE-2024-10727 Phpipam Unspecified vulnerability in PHPipam

A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0.

6.1
2025-03-20 CVE-2024-8021 Gradio Project Unspecified vulnerability in Gradio Project Gradio

An open redirect vulnerability exists in the latest version of gradio-app/gradio.

6.1
2025-03-20 CVE-2024-8101 Aimstack Unspecified vulnerability in Aimstack AIM 3.23.0

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0.

6.1
2025-03-20 CVE-2024-8556 Modelscope Unspecified vulnerability in Modelscope Agentscope

A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch.

6.1
2025-03-20 CVE-2024-9311 Hliu Cross-Site Request Forgery (CSRF) vulnerability in Hliu Large Language and Vision Assistant 1.2.0

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction.

6.1
2025-03-20 CVE-2024-9900 Mudler Cross-site Scripting vulnerability in Mudler Localai 2.21.1

mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality.

6.1
2025-03-19 CVE-2024-55009 Datax Cross-site Scripting vulnerability in Datax Autobib

A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows attackers to execute arbitrary Javascript in the context of a victim's browser via injecting a crafted payload into the WCE=topFrame&WCU= parameter.

6.1
2025-03-20 CVE-2024-12910 Llamaindex Unspecified vulnerability in Llamaindex

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL.

5.9
2025-03-20 CVE-2025-2557 A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0.
5.5
2025-03-20 CVE-2025-1474 Lfprojects Weak Password Requirements vulnerability in Lfprojects Mlflow

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password.

5.5
2025-03-22 CVE-2025-2623 Westboy Cross-site Scripting vulnerability in Westboy Cicadascms 1.0

A vulnerability was found in westboy CicadasCMS 1.0.

5.4
2025-03-21 CVE-2025-2610 Magnussolution Cross-site Scripting vulnerability in Magnussolution Magnusbilling

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting.

5.4
2025-03-21 CVE-2025-2590 Code Projects Code Injection vulnerability in Code-Projects Human Resource Management 1.0.1

A vulnerability was found in code-projects Human Resource Management System 1.0.1.

5.4
2025-03-21 CVE-2025-2582 Simplemachines Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1.4

A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic.

5.4
2025-03-21 CVE-2024-50053 Zohocorp Cross-site Scripting vulnerability in Zohocorp products

Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

5.4
2025-03-20 CVE-2025-1802 Hasthemes Cross-site Scripting vulnerability in Hasthemes HT Mega

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping.

5.4
2025-03-20 CVE-2024-10721 Phpipam Unspecified vulnerability in PHPipam 1.5.2

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2.

5.4
2025-03-20 CVE-2024-12871 Infiniflow Unspecified vulnerability in Infiniflow Ragflow 0.12.0

An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base.

5.4
2025-03-20 CVE-2024-8400 Gaizhenbiao Unspecified vulnerability in Gaizhenbiao Chuanhuchatgpt

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt.

5.4
2025-03-20 CVE-2025-0281 Lunary Cross-site Scripting vulnerability in Lunary

A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier.

5.4
2025-03-19 CVE-2024-53967 Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session.
5.4
2025-03-19 CVE-2024-53968 Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session.
5.4
2025-03-19 CVE-2024-53969 Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session.
5.4
2025-03-19 CVE-2024-53970 Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields.
5.4
2025-03-17 CVE-2025-26393 SolarWinds Service Desk is affected by a broken access control vulnerability.
5.4
2025-03-23 CVE-2025-2651 A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0.
5.3
2025-03-23 CVE-2025-2639 Jizhicms Unspecified vulnerability in Jizhicms

A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic.

5.3
2025-03-23 CVE-2025-2638 Jizhicms Unspecified vulnerability in Jizhicms

A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0.

5.3
2025-03-23 CVE-2025-2637 Jizhicms Unspecified vulnerability in Jizhicms

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0.

5.3
2025-03-22 CVE-2025-2331 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.22.1 via a misconfigured capability check in the 'permissionsCheck' function.
5.3
2025-03-22 CVE-2024-13666 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval.
5.3
2025-03-21 CVE-2025-30348 QT Algorithmic Complexity vulnerability in QT

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

5.3
2025-03-20 CVE-2024-13558 Neahplugins Authorization Bypass Through User-Controlled Key vulnerability in Neahplugins NP Quote Request for Woocommerce

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key.

5.3
2025-03-20 CVE-2024-6838 Lfprojects Unspecified vulnerability in Lfprojects Mlflow 2.13.2

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name.

5.3
2025-03-20 CVE-2025-1766 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24.
5.3
2025-03-19 CVE-2025-2290 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1.
5.3
2025-03-18 CVE-2024-41975 An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs prevents the actual access to the PLCs.
5.3
2025-03-22 CVE-2025-2625 Westboy SQL Injection vulnerability in Westboy Cicadascms 1.0

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0.

4.9
2025-03-22 CVE-2025-1973 The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function.
4.9
2025-03-22 CVE-2025-2478 The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
4.9
2025-03-20 CVE-2024-13920 Webtoffee Path Traversal vulnerability in Webtoffee Order Export & Order Import for Woocommerce

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function.

4.9
2025-03-19 CVE-2025-2511 The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
4.9
2025-03-18 CVE-2025-2487 A flaw was found in the 389-ds-base LDAP Server.
4.9
2025-03-21 CVE-2025-30346 Varnish Software
Varnish Cache Project
HTTP Request Smuggling vulnerability in multiple products

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

4.8
2025-03-23 CVE-2025-2664 A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical.
4.7
2025-03-22 CVE-2025-2477 The CryoKey plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ckemail’ parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping.
4.7
2025-03-19 CVE-2024-45644 IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
4.7
2025-03-17 CVE-2025-2392 A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0.
4.7
2025-03-17 CVE-2025-2389 A vulnerability was found in code-projects Blood Bank Management System 1.0.
4.7
2025-03-23 CVE-2025-2653 A vulnerability was found in FoxCMS 1.25 and classified as problematic.
4.3
2025-03-22 CVE-2024-13768 The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.
4.3
2025-03-22 CVE-2025-0807 The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.
4.3
2025-03-22 CVE-2025-1408 Metagauss Missing Authorization vulnerability in Metagauss Profilegrid

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4.

4.3
2025-03-22 CVE-2024-13737 Stylemixthemes Missing Authorization vulnerability in Stylemixthemes Motors - CAR Dealer, Classifieds & Listing

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57.

4.3
2025-03-21 CVE-2025-2591 A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3.
4.3
2025-03-21 CVE-2025-24920 Mattermost Incorrect Authorization vulnerability in Mattermost Server

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels

4.3
2025-03-21 CVE-2025-27933 Mattermost Incorrect Authorization vulnerability in Mattermost Server

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public

4.3
2025-03-20 CVE-2025-2553 A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2025-2556 A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0.
4.3
2025-03-20 CVE-2025-2549 A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic.
4.3
2025-03-20 CVE-2025-2550 A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic.
4.3
2025-03-20 CVE-2025-2551 A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2025-2552 A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2025-2547 A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2025-2548 A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2025-2546 A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02.
4.3
2025-03-20 CVE-2024-12869 Infiniflow Unspecified vulnerability in Infiniflow Ragflow 0.12.0

In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list.

4.3
2025-03-20 CVE-2024-13060 Mintplexlabs Unspecified vulnerability in Mintplexlabs Anythingllm Docker

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie.

4.3
2025-03-20 CVE-2025-1314 The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5.
4.3
2025-03-19 CVE-2024-7631 A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json.
4.3
2025-03-19 CVE-2024-25132 A flaw was found in the Hive hibernation controller component of OpenShift Dedicated.
4.3
2025-03-17 CVE-2025-2354 A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic.
4.3
2025-03-21 CVE-2025-30345 Openslides Cross-site Scripting vulnerability in Openslides 3.2

An issue was discovered in OpenSlides before 4.2.5.

4.1
2025-03-18 CVE-2024-49822 IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF).
4.1

16 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-03-21 CVE-2025-30344 Openslides Information Exposure Through Discrepancy vulnerability in Openslides 3.2

An issue was discovered in OpenSlides before 4.2.5.

3.7
2025-03-17 CVE-2025-2356 A vulnerability was found in BlackVue App 3.65 on Android.
3.7
2025-03-17 CVE-2025-2377 A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic.
3.5
2025-03-17 CVE-2025-2375 A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
3.5
2025-03-17 CVE-2025-2371 A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0.
3.5
2025-03-17 CVE-2025-2364 A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0.
3.5
2025-03-21 CVE-2025-2588 Augeas Unspecified vulnerability in Augeas 1.14.1

A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic.

3.3
2025-03-17 CVE-2025-2355 A vulnerability was found in BlackVue App 3.65 on Android and classified as problematic.
3.3
2025-03-20 CVE-2025-2555 A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0.
2.9
2025-03-22 CVE-2025-1972 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2.
2.7
2025-03-21 CVE-2025-27715 Mattermost Incorrect Authorization vulnerability in Mattermost Server

Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.

2.7
2025-03-22 CVE-2025-2617 A vulnerability classified as problematic was found in yangyouwang ??? crud ???????? 1.0.0.
2.4
2025-03-22 CVE-2025-2616 A vulnerability classified as problematic has been found in yangyouwang ??? crud ???????? 1.0.0.
2.4
2025-03-18 CVE-2025-2491 A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5.
2.4
2025-03-18 CVE-2025-2490 A vulnerability was found in Dromara ujcms 9.7.5.
2.4
2025-03-17 CVE-2025-2366 A vulnerability, which was classified as problematic, was found in gougucms 4.08.18.
2.4