Latest CVE Feed
-
9.3
CRITICALCVE-2025-40618
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
6.4
MEDIUMCVE-2025-3521
The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social Link icons in all versions up to, and including, 3.4.0 due to insufficient input sani... Read more
Affected Products : team_members- Published: May. 01, 2025
- Modified: May. 02, 2025
-
7.6
HIGHCVE-2025-23178
CWE-923: Improper Restriction of Communication Channel to Intended Endpoints... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
8.7
HIGHCVE-2025-27611
base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. T... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.4
MEDIUMCVE-2025-24348
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the wireless network configuration file via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
7.6
HIGH- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
4.8
MEDIUMCVE-2025-0716
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/a... Read more
Affected Products : angular- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-4076
A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the component Password Handler. The manipulation of the argument routepwd ... Read more
Affected Products : bl-ac3600_firmware- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
3.2
LOWCVE-2023-37517
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
8.8
HIGHCVE-2025-24351
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arbitrary OS commands in the context of user “root” via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-24340
A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker to recover the plaintext passwords of other users.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2025-4075
A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Email with the input "><script>alert(1)</script> leads to c... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.1
MEDIUMCVE-2025-40616
Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
7.1
HIGHCVE-2025-24349
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to delete the configuration of physical network interfaces via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
4.3
MEDIUMCVE-2025-4095
Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being a... Read more
Affected Products : desktop- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.2
MEDIUMCVE-2025-3911
Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs c... Read more
Affected Products : desktop- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.7
MEDIUMCVE-2024-11994
APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs.... Read more
Affected Products : apm_server- Published: May. 01, 2025
- Modified: May. 02, 2025
-
6.2
MEDIUMCVE-2023-46669
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elasti... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
-
8.8
HIGHCVE-2025-23254
NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information d... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
-
4.4
MEDIUMCVE-2024-52976
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configuratio... Read more
Affected Products : elastic_agent- Published: May. 01, 2025
- Modified: May. 02, 2025