Latest CVE Feed
-
9.8
CRITICALCVE-2024-53544
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-53543
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-53542
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-27141
Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with imperson... Read more
Affected Products : metabase- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2025-27140
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary co... Read more
Affected Products : wegia- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25513
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.... Read more
Affected Products : seacms- Published: Feb. 24, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-57608
An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-27137
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templates. Templates a... Read more
Affected Products : dependency-track- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Supply Chain
-
9.8
CRITICALCVE-2025-26533
An SQL injection risk was identified in the module list filter within course search.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-26532
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-26531
Insufficient capability checks made it possible to disable badges a user does not have permission to access.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
8.3
HIGHCVE-2025-26530
The question bank filter required additional sanitizing to prevent a reflected XSS risk.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2025-26529
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-26528
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-26527
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-26526
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-26525
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).... Read more
Affected Products : moodle- Published: Feb. 24, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2025-27364
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server tha... Read more
Affected Products : caldera- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-27133
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbit... Read more
Affected Products : wegia- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-27112
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary u... Read more
Affected Products : navidrome- Published: Feb. 24, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Authentication