CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-24033

Description: @fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `saveRequestFiles` function does not delete the uploaded temporary files when user cancels the request. The issue is fixed in versions 8.3.1 and 9.0.3. As a workaround, do not use `saveRequestFiles`.

CVSS: HIGH (7.5)

EPSS Score: 0.05%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-24030

Description: Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. A user with access to the Kubernetes cluster can use a path traversal attack to execute Envoy Admin interface commands on proxies managed by any version of Envoy Gateway prior to 1.2.6. The admin interface can be used to terminate the Envoy process and extract the Envoy configuration (possibly containing confidential data). Version 1.2.6 fixes the issue. As a workaround, the `EnvoyProxy` API can be used to apply a bootstrap config patch that restricts access strictly to the prometheus stats endpoint. Find below an example of such a bootstrap patch.

CVSS: HIGH (7.1)

EPSS Score: 0.05%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23960

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in basteln3rk Save & Import Image from URL allows Reflected XSS. This issue affects Save & Import Image from URL: from n/a through 0.7.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23894

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tatsuya Fukata, Alexander Ovsov wp-flickr-press allows Reflected XSS. This issue affects wp-flickr-press: from n/a through 2.6.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23836

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SuryaBhan Custom Coming Soon allows Reflected XSS. This issue affects Custom Coming Soon: from n/a through 2.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23835

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Legal + allows Reflected XSS. This issue affects Legal +: from n/a through 1.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23834

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Links/Problem Reporter allows Reflected XSS. This issue affects Links/Problem Reporter: from n/a through 2.6.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23733

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sayocode SC Simple Zazzle allows Reflected XSS. This issue affects SC Simple Zazzle: from n/a through 1.1.6.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23730

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FLX Dashboard Groups allows Reflected XSS. This issue affects FLX Dashboard Groups: from n/a through 0.0.7.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23729

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fures XTRA Settings allows Reflected XSS. This issue affects XTRA Settings: from n/a through 2.1.8.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)