CVE-2025-2197 - "Mozilla Browser Type Confusion RCE"
CVE ID : CVE-2025-2197
Published : April 17, 2025, 10:15 a.m. | 26 minutes ago
Description : Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-2197
Published : April 17, 2025, 10:15 a.m. | 26 minutes ago
Description : Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29931 - "TeleControl Server Basic Remote DoS Vulnerability"
CVE ID : CVE-2025-29931
Published : April 17, 2025, 11:15 a.m. | 3 hours, 26 minutes ago
Description : A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not properly validate a length field in a serialized message which it uses to determine the amount of memory to be allocated for deserialization. This could allow an unauthenticated remote attacker to cause the application to allocate exhaustive amounts of memory and subsequently create a partial denial of service condition. Successful exploitation is only possible in redundant Telecontrol Server Basic setups and only if the connection between the redundant servers has been disrupted.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29931
Published : April 17, 2025, 11:15 a.m. | 3 hours, 26 minutes ago
Description : A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not properly validate a length field in a serialized message which it uses to determine the amount of memory to be allocated for deserialization. This could allow an unauthenticated remote attacker to cause the application to allocate exhaustive amounts of memory and subsequently create a partial denial of service condition. Successful exploitation is only possible in redundant Telecontrol Server Basic setups and only if the connection between the redundant servers has been disrupted.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26477 - Dell ECS Improper Input Validation Code Execution Vulnerability
CVE ID : CVE-2025-26477
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-26477
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-26478 - Dell ECS Certificate Validation Vulnerability
CVE ID : CVE-2025-26478
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-26478
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3453 - WordPress Password Protect Sensitive Information Exposure
CVE ID : CVE-2025-3453
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This makes it possible for unauthenticated attackers to extract sensitive data including all protected site content if the 'Use Transient' setting is enabled.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3453
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This makes it possible for unauthenticated attackers to extract sensitive data including all protected site content if the 'Use Transient' setting is enabled.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3479 - Forminator Forms - WordPress Stripe Payment Intent Order Replay Vulnerability
CVE ID : CVE-2025-3479
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3479
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 1.42.0 via the 'handle_stripe_single' function due to insufficient validation on a user controlled key. This makes it possible for unauthenticated attackers to reuse a single Stripe PaymentIntent for multiple transactions. Only the first transaction is processed via Stripe, but the plugin sends a successful email message for each transaction, which may trick an administrator into fulfilling each order.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3487 - Forminator Forms - WordPress Stored Cross-Site Scripting
CVE ID : CVE-2025-3487
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3487
Published : April 17, 2025, 12:15 p.m. | 2 hours, 26 minutes ago
Description : The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘limit’ parameter in all versions up to, and including, 1.42.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3760 - Liferay Portal Stored Cross-Site Scripting (XSS)
CVE ID : CVE-2025-3760
Published : April 17, 2025, 1:15 p.m. | 1 hour, 26 minutes ago
Description : A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3760
Published : April 17, 2025, 1:15 p.m. | 1 hour, 26 minutes ago
Description : A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29015 - Code Astro Internet Banking System Cross Site Scripting (XSS)
CVE ID : CVE-2025-29015
Published : April 17, 2025, 2:15 p.m. | 26 minutes ago
Description : Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29015
Published : April 17, 2025, 2:15 p.m. | 26 minutes ago
Description : Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43013 - JetBrains Toolbox App SSH Authentication Unencrypted Credential Transmission Vulnerability
CVE ID : CVE-2025-43013
Published : April 17, 2025, 4:15 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43013
Published : April 17, 2025, 4:15 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43014 - JetBrains Toolbox App SSH Plugin Unauthenticated Remote Command Execution
CVE ID : CVE-2025-43014
Published : April 17, 2025, 4:16 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43014
Published : April 17, 2025, 4:16 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43015 - JetBrains RubyMine Remote Port Overwrite
CVE ID : CVE-2025-43015
Published : April 17, 2025, 4:16 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43015
Published : April 17, 2025, 4:16 p.m. | 2 hours, 28 minutes ago
Description : In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-40124 - Pydio Core Cross Site Scripting (XSS)
CVE ID : CVE-2024-40124
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-40124
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29039 - Dlink DIR 832x Buffer Overflow Vulnerability
CVE ID : CVE-2025-29039
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29039
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29180 - FOXCMS Blind SQL Injection
CVE ID : CVE-2025-29180
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29180
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29181 - FOXCMS SQL Injection
CVE ID : CVE-2025-29181
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29181
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29661 - Litepubl CMS Remote Code Execution Vulnerability
CVE ID : CVE-2025-29661
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29661
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-29662 - LandChat Remote Code Execution (RCE)
CVE ID : CVE-2025-29662
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-29662
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2947 - IBM i Privilege Escalation Vulnerability
CVE ID : CVE-2025-2947
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-2947
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-32415 - Libxml2 Heap-Based Buffer Underflow Vulnerability
CVE ID : CVE-2025-32415
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-32415
Published : April 17, 2025, 5:15 p.m. | 1 hour, 28 minutes ago
Description : In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2020-36789 - Linux Kernel CAN Network Stack NULL Pointer Dereference Vulnerability
CVE ID : CVE-2020-36789
Published : April 17, 2025, 6:15 p.m. | 28 minutes ago
Description : In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get(). The skb is finally freed by one of the in-irq-context safe functions: dev_consume_skb_any() or dev_kfree_skb_any(). The "any" version is used because some drivers might call can_get_echo_skb() in a normal context. The reason for this issue to occur is that initially, in the core network stack, loopback skb were not supposed to be received in hardware IRQ context. The CAN stack is an exeption. This bug was previously reported back in 2017 in [1] but the proposed patch never got accepted. While [1] directly modifies net/core/dev.c, we try to propose here a smoother modification local to CAN network stack (the assumption behind is that only CAN devices are affected by this issue). [1] http://lore.kernel.org/r/57a3ffb6-3309-3ad5-5a34-e93c3fe3614d@cetitec.com
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2020-36789
Published : April 17, 2025, 6:15 p.m. | 28 minutes ago
Description : In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case), the 'WARN_ON(in_irq)' in net/core/skbuff.c#skb_release_head_state() might be triggered, under network congestion circumstances, together with the potential risk of a NULL pointer dereference. The root cause of this issue is the call to kfree_skb() instead of dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog(). This patch prevents the skb to be freed within the call to netif_rx() by incrementing its reference count with skb_get(). The skb is finally freed by one of the in-irq-context safe functions: dev_consume_skb_any() or dev_kfree_skb_any(). The "any" version is used because some drivers might call can_get_echo_skb() in a normal context. The reason for this issue to occur is that initially, in the core network stack, loopback skb were not supposed to be received in hardware IRQ context. The CAN stack is an exeption. This bug was previously reported back in 2017 in [1] but the proposed patch never got accepted. While [1] directly modifies net/core/dev.c, we try to propose here a smoother modification local to CAN network stack (the assumption behind is that only CAN devices are affected by this issue). [1] http://lore.kernel.org/r/57a3ffb6-3309-3ad5-5a34-e93c3fe3614d@cetitec.com
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...