Latest CVE Feed
-
7.1
HIGHCVE-2025-23424
Cross-Site Request Forgery (CSRF) vulnerability in Brian Novotny – Creative Software Design Solutions Marquee Style RSS News Ticker allows Cross Site Request Forgery.This issue affects Marquee Style RSS News Ticker: from n/a through 3.2.0.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-23423
Missing Authorization vulnerability in Smackcoders SendGrid for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a through 1.4.... Read more
Affected Products : sendgrid- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2024-56515
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which claims to be either of these types and request a thumbn... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2024-56136
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated user c... Read more
- Published: Jan. 16, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2024-55954
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended privilege hierarch... Read more
Affected Products : openobserve- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-52791
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return large amounts of JSON back to MMR for parsing. In parsing,... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-52602
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This is fi... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-36403
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauthenticated adversary can induce it to download and cache large amounts of re... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-36402
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to th... Read more
Affected Products : matrix-media-repo- Published: Jan. 16, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-20630
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-20621
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-57684
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2024-57680
An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-57679
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57678
An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-57677
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57676
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication