Latest CVE Feed
-
7.5
HIGHCVE-2025-32021
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation ... Read more
Affected Products : weblate- Published: Apr. 15, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-32968
XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arbitrar... Read more
Affected Products : xwiki- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-31117
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauth... Read more
Affected Products : openemr- Published: Mar. 31, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Server-Side Request Forgery
-
6.4
MEDIUMCVE-2025-30149
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulner... Read more
Affected Products : openemr- Published: Mar. 31, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-29911
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer o... Read more
Affected Products : cryptolib- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-29910
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory leak vulnerabil... Read more
Affected Products : cryptolib- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29909
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and pr... Read more
Affected Products : cryptolib- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.9
CRITICALCVE-2024-55662
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on th... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-55876
XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki withou... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
9.9
CRITICALCVE-2024-55877
XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. Thi... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-55879
XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromise... Read more
Affected Products : xwiki- Published: Dec. 12, 2024
- Modified: Apr. 30, 2025
-
8.7
HIGHCVE-2025-29924
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent unregis... Read more
Affected Products : xwiki- Published: Mar. 19, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-29925
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if... Read more
Affected Products : xwiki- Published: Mar. 19, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Information Disclosure
-
4.7
MEDIUMCVE-2025-32783
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Rights. Th... Read more
Affected Products : xwiki- Published: Apr. 16, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-32969
XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQ... Read more
Affected Products : xwiki- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45429
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Denial of Service
-
3.5
LOWCVE-2025-1524
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1525
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-29046
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29047
Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption