Latest CVE Feed
-
5.4
MEDIUMCVE-2025-1015
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If a... Read more
Affected Products : thunderbird- Published: Feb. 04, 2025
- Modified: Mar. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-1014
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
-
6.5
MEDIUMCVE-2025-1013
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 1... Read more
- Published: Feb. 04, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-1011
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 13... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1010
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1009
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0510
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vulnerability affects Thunderbird < 128.7 and Thunderbird < 135.... Read more
Affected Products : thunderbird- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
-
4.8
MEDIUMCVE-2024-11623
Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application icons. This action could only be performed by an authenticated admin user. The issue was fixed in 2024.10.4 release.... Read more
Affected Products : authentik- Published: Feb. 04, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13699
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for aut... Read more
Affected Products : qi_addons_for_elementor- Published: Feb. 04, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-24860
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can up... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2025-0890
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have t... Read more
Affected Products : vmg4325-b10a_firmware- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
-
5.3
MEDIUMCVE-2024-27137
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the J... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-23015
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting d... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jul. 14, 2025
-
8.8
HIGHCVE-2024-40891
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating sys... Read more
Affected Products : vmg1312-b10a_firmware vmg4380-b10a_firmware vmg8324-b10a_firmware vmg8924-b10a_firmware sbg3300-n000_firmware sbg3300-nb00_firmware sbg3500-n000_firmware vmg8324-b10a vmg1312-b10a vmg4380-b10a +17 more products- Actively Exploited
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-40890
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS)... Read more
Affected Products : vmg1312-b10a_firmware vmg4380-b10a_firmware vmg8324-b10a_firmware vmg8924-b10a_firmware sbg3300-n000_firmware sbg3300-nb00_firmware sbg3500-n000_firmware vmg8324-b10a vmg1312-b10a vmg4380-b10a +17 more products- Actively Exploited
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2024-13733
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and including, 1.7 due to insufficient input sanitization and output esc... Read more
Affected Products : skt_blocks- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-13529
The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'socialv_send_download_file' function in all versions up to, and including, 2.0.15. This ... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-13510
The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update ... Read more
Affected Products : shopsite- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2024-13356
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unaut... Read more
Affected Products : dsgvo_all_in_one_for_wp- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Request Forgery