Latest CVE Feed
-
9.4
CRITICALCVE-2023-5878
Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to p... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2022-31764
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fi... Read more
Affected Products : shardingsphere_elasticjob-ui- Published: Feb. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-1076
A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-1074
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch... Read more
Affected Products : qloapps- Published: Feb. 06, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2024-24911
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Se... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-57962
Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-57961
Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
7.7
HIGHCVE-2024-57960
Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2024-57959
Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2024-57958
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.... Read more
- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-57957
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-57956
Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-57955
Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-57954
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-12602
Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Feb. 06, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-0982
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will ... Read more
Affected Products : application_integration- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
-
7.5
HIGHCVE-2024-45626
Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this is... Read more
- Published: Feb. 06, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Denial of Service
-
8.6
HIGHCVE-2024-37358
Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version... Read more
- Published: Feb. 06, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-0859
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, ... Read more
Affected Products : post_and_page_builder_by_boldgrid_-_visual_drag_and_drop_editor post_and_page_builder- Published: Feb. 06, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Path Traversal
-
6.3
MEDIUMCVE-2025-24845
Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where t... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Denial of Service