CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2024-0199

Description: An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

CVSS: HIGH (7.7)

EPSS Score: 0.01%

SSVC Exploitation: poc

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2024-0049

Description: In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS: HIGH (7.8)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2024-41357

Description: phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

CVSS: HIGH (7.1)

EPSS Score: 0.06%

SSVC Exploitation: poc

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-3693

Description: A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cgiWifiRadioSet of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Eine kritische Schwachstelle wurde in Tenda W12 3.0.0.5 ausgemacht. Dies betrifft die Funktion cgiWifiRadioSet der Datei /bin/httpd. Durch das Manipulieren mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.

CVSS: HIGH (8.7)

EPSS Score: 0.05%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39592

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite allows PHP Local File Inclusion. This issue affects Subscribe to Unlock Lite: from n/a through 1.3.0.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39584

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.25.

CVSS: HIGH (7.5)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39570

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS: HIGH (8.8)

EPSS Score: 0.13%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39566

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel allows Blind SQL Injection. This issue affects Hostel: from n/a through 1.1.5.6.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39548

Description: Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban allows Stored XSS. This issue affects Right Click Disable OR Ban: from n/a through 1.1.17.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (2 months ago)

CVE-2025-39547

Description: Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser allows Stored XSS. This issue affects Internal Link Optimiser: from n/a through 5.1.3.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 16th, 2025 (2 months ago)