CVE ID : CVE-2025-28099

Published : April 21, 2025, 5:15 p.m. | 1 hour, 47 minutes ago

Description : opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28102

Published : April 21, 2025, 5:15 p.m. | 1 hour, 47 minutes ago

Description : A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.

Severity: 6.1 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-29446

Published : April 21, 2025, 5:15 p.m. | 1 hour, 47 minutes ago

Description : open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2024-57394

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : The quarantine – restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28103

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-28104

Published : April 21, 2025, 6:15 p.m. | 47 minutes ago

Description : Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-39596

Published : April 17, 2025, 4:15 p.m. | 3 days, 20 hours ago

Description : Weak Authentication vulnerability in Quentn.com GmbH Quentn WP allows Privilege Escalation. This issue affects Quentn WP: from n/a through 1.2.8.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-43015

Published : April 17, 2025, 4:16 p.m. | 3 days, 20 hours ago

Description : In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

Severity: 8.3 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-29662

Published : April 17, 2025, 5:15 p.m. | 3 days, 19 hours ago

Description : A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2024-55211

Published : April 17, 2025, 6:15 p.m. | 3 days, 18 hours ago

Description : An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

Severity: 8.4 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32408

Published : April 21, 2025, 1:15 p.m. | 45 minutes ago

Description : In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…