High · CVSS 7.5
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.
Published Feb 26, 2024 · Updated Apr 22, 2025
High · CVSS 7.5
The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.
Published Feb 27, 2024 · Updated Apr 22, 2025
Critical · CVSS 9.8
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
Published Feb 29, 2024 · Updated Apr 22, 2025
Critical · CVSS 9.1
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
Published Feb 28, 2023 · Updated Apr 14, 2025
Critical · CVSS 9.1
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
Published Feb 28, 2023 · Updated Apr 14, 2025
High · CVSS 8.8
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Published Feb 14, 2023 · Updated Apr 12, 2025
High · CVSS 7.8
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Published Feb 14, 2023 · Updated Apr 12, 2025
High · CVSS 8.8
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published Feb 14, 2023 · Updated Apr 12, 2025
Medium · CVSS 6.9
The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.
Published Feb 11, 2025 · Updated Apr 8, 2025
Medium · CVSS 5.1
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Published Feb 24, 2023 · Updated Apr 3, 2025
Critical · CVSS 10
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
Published Feb 16, 2023 · Updated Apr 1, 2025
Medium · CVSS 5.3
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
Published Feb 16, 2023 · Updated Apr 1, 2025
Critical · CVSS 9.9
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
Published Feb 16, 2023 · Updated Apr 1, 2025
Medium · CVSS 6.3
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
Published Feb 1, 2023 · Updated Mar 29, 2025
Medium · CVSS 4.3
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
Published Feb 1, 2023 · Updated Mar 29, 2025
High · CVSS 7.5
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled.
This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Published Feb 13, 2024 · Updated Mar 28, 2025
Critical · CVSS 9.8
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
Published Feb 18, 2024 · Updated Mar 28, 2025
High · CVSS 7.8
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published Feb 15, 2024 · Updated Mar 28, 2025
Critical · CVSS 9.8
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Published Feb 28, 2024 · Updated Mar 28, 2025
High · CVSS 7.5
Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.
Published Feb 18, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.5
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue.
More Details:
Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation.
This vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.
Published Feb 27, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.1
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)
Published Feb 13, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.3
Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.
Published Feb 18, 2024 · Updated Mar 27, 2025
High · CVSS 7.5
Arbitrary File Read Vulnerability in Apache Dolphinscheduler.
This issue affects Apache DolphinScheduler: before 3.2.1.
We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
Published Feb 20, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.5
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with an invalid token. This could allow an unauthenticated attacker to view, update, delete or create an IdP configuration. IBM X-Force ID: 261130.
Published Feb 29, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.5
Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.
Published Feb 16, 2024 · Updated Mar 27, 2025
High · CVSS 7.5
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
Published Feb 18, 2024 · Updated Mar 27, 2025
High · CVSS 8.1
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 8.8
As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055.
Published Feb 1, 2023 · Updated Mar 27, 2025
Critical · CVSS 9.1
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.
Published Feb 1, 2023 · Updated Mar 27, 2025
Critical · CVSS 9.3
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.2
Cross-site Scripting (XSS) - Stored in GitHub repository projectsend/projectsend prior to r1606.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 8.8
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 4.8
The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Published Feb 27, 2024 · Updated Mar 27, 2025
Medium · CVSS 6.1
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.1
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.1
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.1
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.5
Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.
Published Feb 1, 2023 · Updated Mar 27, 2025
Critical · CVSS 9.8
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.5
Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.2
An arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafted JPG file.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.1
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.1
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 6.5
lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.
Published Feb 1, 2023 · Updated Mar 27, 2025
Medium · CVSS 4.3
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The supported version that is affected is 8.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published Feb 17, 2024 · Updated Mar 27, 2025
High · CVSS 7.5
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 8.8
NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.5
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 https://github.com/apache/inlong/pull/7214 to solve it.
Published Feb 1, 2023 · Updated Mar 27, 2025
High · CVSS 7.5
Dell Enterprise SONiC OS, 3.5.3, 4.0.0, 4.0.1, 4.0.2, contains an "Uncontrolled Resource Consumption vulnerability" in authentication component. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to uncontrolled resource consumption by creating permanent home directories for unauthenticated users.
Published Feb 2, 2023 · Updated Mar 27, 2025