| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-23465 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magent Vampire Character Manager vampire-character allows Reflected XSS.This issue affects Vampire Character Manager: from n/a through <= 2.13. | ||
| CVE-2025-23464 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keir Whitaker Twitter News Feed twitter-news-feed allows Reflected XSS.This issue affects Twitter News Feed: from n/a through <= 1.1.1. | ||
| CVE-2025-23451 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome Twitter Feeds awesome-twitter-feeds allows Reflected XSS.This issue affects Awesome Twitter Feeds: from n/a through <= 1.0. | ||
| CVE-2025-23450 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4. | ||
| CVE-2025-23447 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kundan Yevale Smooth Dynamic Slider smooth-dynamic-slider allows Reflected XSS.This issue affects Smooth Dynamic Slider: from n/a through <= 1.0. | ||
| CVE-2025-23446 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: from n/a through <= 0.4.5. | ||
| CVE-2025-23441 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6. | ||
| CVE-2025-23439 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0. | ||
| CVE-2025-23437 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nord_tramper ntp-header-images header-images-rotator allows Reflected XSS.This issue affects ntp-header-images: from n/a through <= 1.2. | ||
| CVE-2025-23433 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS vcos allows Reflected XSS.This issue affects vcOS: from n/a through <= 1.4.0. | ||
| CVE-2025-23425 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark marekkis-watermark allows Reflected XSS.This issue affects Marekkis Watermark: from n/a through <= 0.9.4. | ||
| CVE-2025-21424 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while calling the NPU driver APIs concurrently. | ||
| CVE-2025-0475 | Hig | 0.57 | 8.7 | 0.00 | Mar 3, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances. | ||
| CVE-2024-53034 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset. | ||
| CVE-2024-53033 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address. | ||
| CVE-2024-53032 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur in keyboard virtual device due to guest VM interaction. | ||
| CVE-2024-53031 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53030 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing input message passed from FE driver. | ||
| CVE-2024-53029 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53028 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while processing message from frontend during allocation. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-53024 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption in display driver while detaching a device. | ||
| CVE-2024-53023 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while accessing a variable during extended back to back tests. | ||
| CVE-2024-53022 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during communication between primary and guest VM. | ||
| CVE-2024-53014 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur while validating ports and channels in Audio driver. | ||
| CVE-2024-53012 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur due to improper input validation in clock device. | ||
| CVE-2024-53011 | Hig | 0.51 | 7.9 | 0.00 | Mar 3, 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. | ||
| CVE-2024-49836 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during the synchronization of the camera`s frame processing pipeline. | ||
| CVE-2024-45580 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. | ||
| CVE-2024-43062 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization. | ||
| CVE-2024-43061 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive. | ||
| CVE-2024-43060 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. | ||
| CVE-2024-43059 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. | ||
| CVE-2024-43057 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing command in Glink linux. | ||
| CVE-2024-43055 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing camera use case IOCTL call. | ||
| CVE-2025-24846 | Hig | 0.49 | 7.5 | 0.01 | Mar 3, 2025 | Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted… | ||
| CVE-2025-24654 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07. | ||
| CVE-2025-1859 | Hig | 0.47 | 7.3 | 0.00 | Mar 3, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | ||
| CVE-2025-1858 | Hig | 0.47 | 7.3 | 0.01 | Mar 3, 2025 | A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2025-1857 | Hig | 0.47 | 7.3 | 0.01 | Mar 3, 2025 | A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. It is possible to initiate the… | ||
| CVE-2025-1856 | Hig | 0.47 | 7.3 | 0.01 | Mar 3, 2025 | A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. The attack may be… | ||
| CVE-2025-1723 | Hig | 0.53 | 8.1 | 0.01 | Mar 3, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | ||
| CVE-2025-1853 | Hig | 0.57 | 8.8 | 0.01 | Mar 3, 2025 | A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack… | ||
| CVE-2025-1852 | Hig | 0.57 | 8.8 | 0.01 | Mar 3, 2025 | A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be… | ||
| CVE-2025-1851 | Hig | 0.57 | 8.8 | 0.01 | Mar 3, 2025 | A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to… | ||
| CVE-2025-1850 | Hig | 0.47 | 7.3 | 0.01 | Mar 3, 2025 | A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of the file /university.php. The manipulation of the argument book_name leads to sql injection. The attack may be… | ||
| CVE-2025-20645 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue… | ||
| CVE-2025-25951 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information. | ||
| CVE-2025-25950 | Hig | 0.53 | 8.1 | 0.00 | Mar 3, 2025 | Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account. | ||
| CVE-2025-1841 | Hig | 0.47 | 7.3 | 0.00 | Mar 3, 2025 | A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the argument startDate/endDate leads to sql injection. It is possible to initiate the… |
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magent Vampire Character Manager vampire-character allows Reflected XSS.This issue affects Vampire Character Manager: from n/a through <= 2.13.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keir Whitaker Twitter News Feed twitter-news-feed allows Reflected XSS.This issue affects Twitter News Feed: from n/a through <= 1.1.1.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome Twitter Feeds awesome-twitter-feeds allows Reflected XSS.This issue affects Awesome Twitter Feeds: from n/a through <= 1.0.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kundan Yevale Smooth Dynamic Slider smooth-dynamic-slider allows Reflected XSS.This issue affects Smooth Dynamic Slider: from n/a through <= 1.0.
- risk 0.46cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: from n/a through <= 0.4.5.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nord_tramper ntp-header-images header-images-rotator allows Reflected XSS.This issue affects ntp-header-images: from n/a through <= 1.2.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS vcos allows Reflected XSS.This issue affects vcOS: from n/a through <= 1.4.0.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark marekkis-watermark allows Reflected XSS.This issue affects Marekkis Watermark: from n/a through <= 0.9.4.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while calling the NPU driver APIs concurrently.
- risk 0.57cvss 8.7epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing input message passed from FE driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while processing message from frontend during allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in display driver while detaching a device.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while accessing a variable during extended back to back tests.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during communication between primary and guest VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur while validating ports and channels in Audio driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur due to improper input validation in clock device.
- risk 0.51cvss 7.9epss 0.00
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing command in Glink linux.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing camera use case IOCTL call.
- risk 0.49cvss 7.5epss 0.01
Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted…
- risk 0.46cvss 7.1epss 0.00
Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.
- risk 0.47cvss 7.3epss 0.00
A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has…
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument employeeid leads to sql injection. It is possible to initiate the…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. The attack may be…
- risk 0.53cvss 8.1epss 0.01
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be…
- risk 0.57cvss 8.8epss 0.01
A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of the file /university.php. The manipulation of the argument book_name leads to sql injection. The attack may be…
- risk 0.51cvss 7.8epss 0.00
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue…
- risk 0.49cvss 7.5epss 0.00
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.
- risk 0.53cvss 8.1epss 0.00
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
- risk 0.47cvss 7.3epss 0.00
A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manipulation of the argument startDate/endDate leads to sql injection. It is possible to initiate the…