CVE-2025-31282 - Trend Vision One User Account Privilege Escalation
CVE ID : CVE-2025-31282
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31282
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31283 - Trend Vision One Escalation of Privilege Vulnerability
CVE ID : CVE-2025-31283
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31283
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31284 - Trend Vision One Status Privilege Escalation Vulnerability
CVE ID : CVE-2025-31284
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31284
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31285 - Trend Vision One Role Name Privilege Escalation Vulnerability
CVE ID : CVE-2025-31285
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31285
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31286 - Trend Vision One HTML Injection Vulnerability
CVE ID : CVE-2025-31286
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31286
Published : April 2, 2025, 5:15 p.m. | 1 hour, 16 minutes ago
Description : An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Severity: 0.0 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-37917 - Pexip Infinity Denial of Service
CVE ID : CVE-2024-37917
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-37917
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-38392 - Pexip Infinity Connect Remote Code Execution
CVE ID : CVE-2024-38392
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-38392
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22923 - OS4ED openSIS File Deletion Directory Traversal
CVE ID : CVE-2025-22923
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22923
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22924 - OS4ED openSIS SQL Injection Vulnerability
CVE ID : CVE-2025-22924
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22924
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-22925 - OS4ED openSIS SQL Injection
CVE ID : CVE-2025-22925
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-22925
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29062 - BL-AC2100 Remote Code Execution Vulnerability
CVE ID : CVE-2025-29062
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29062
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in the set_LimitClient_cfg of the goahead webservice.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29063 - BL-AC2100 Router Code Execution Vulnerability
CVE ID : CVE-2025-29063
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29063
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29085 - Vipshop Saturn SQL Injection Vulnerability
CVE ID : CVE-2025-29085
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29085
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29719 - SourceCodester rems Employee Management System Cross Site Scripting (XSS)
CVE ID : CVE-2025-29719
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29719
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2704 - OpenVPN TLS-crypt-v2 Denial of Service
CVE ID : CVE-2025-2704
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-2704
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30080 - Pexip Infinity Denial of Service
CVE ID : CVE-2025-30080
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-30080
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3118 - SourceCodester Online Tutor Portal SQL Injection
CVE ID : CVE-2025-3118
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3118
Published : April 2, 2025, 9:15 p.m. | 1 hour, 17 minutes ago
Description : A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-0257 - HCL DevOps Deploy/HCL Launch Agent Relay Authentication Bypass Vulnerability
CVE ID : CVE-2025-0257
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-0257
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-27608 - Arduino IDE Theia Framework Electron Self Cross-Site Scripting (XSS)
CVE ID : CVE-2025-27608
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings section of the Arduino IDE interface. In the vulnerable versions, any values entered in this field are directly displayed to the user through a notification tooltip object, without a proper output encoding routine, due to the underlying ElectronJS engine interpretation. This vulnerability exposes the input parameter to Self-XSS attacks, which may lead to security risks depending on where the malicious payload is injected. This vulnerability is fixed in 2.3.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-27608
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Arduino IDE 2.x is an IDE based on the Theia IDE framework and built with Electron. A Self Cross-Site Scripting (XSS) vulnerability has been identified within the Arduino-IDE prior to version v2.3.5. The vulnerability occurs in the Additional Board Manager URLs field, which can be found in the Preferences -> Settings section of the Arduino IDE interface. In the vulnerable versions, any values entered in this field are directly displayed to the user through a notification tooltip object, without a proper output encoding routine, due to the underlying ElectronJS engine interpretation. This vulnerability exposes the input parameter to Self-XSS attacks, which may lead to security risks depending on where the malicious payload is injected. This vulnerability is fixed in 2.3.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-30218 - Next.js Cross-Origin Request Exposure
CVE ID : CVE-2025-30218
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-30218
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-31477 - Tauri Shell Plugin Remote Code Execution Vulnerability
CVE ID : CVE-2025-31477
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be restricted to a reasonable number of protocols like https or mailto by default. This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like file://, smb://, or nfs:// and others to be opened by the system registered protocol handler. By passing untrusted user input to the open endpoint these potentially dangerous protocols can be abused to gain remote code execution on the system. This either requires direct exposure of the endpoint to application users or code execution in the frontend of a Tauri application. This vulnerability is fixed in 2.2.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-31477
Published : April 2, 2025, 10:15 p.m. | 17 minutes ago
Description : The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be restricted to a reasonable number of protocols like https or mailto by default. This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like file://, smb://, or nfs:// and others to be opened by the system registered protocol handler. By passing untrusted user input to the open endpoint these potentially dangerous protocols can be abused to gain remote code execution on the system. This either requires direct exposure of the endpoint to application users or code execution in the frontend of a Tauri application. This vulnerability is fixed in 2.2.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...