Common Vulnerabilities and Exposures (CVEs)

CVE ID : CVE-2024-30115

Published : April 30, 2025, 10:15 p.m. | 54 minutes ago

Description : Insufficient sanitization policy in HCL Leap
allows client-side script injection in the deployed application through the
HTML widget.

Severity: 6.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2024-30146

Published : April 30, 2025, 10:15 p.m. | 54 minutes ago

Description : Improper access control of endpoint in HCL Domino Leap
allows certain admin users to import applications from the
server’s filesystem.

Severity: 4.1 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4140

Published : April 30, 2025, 10:15 p.m. | 1 hour, 31 minutes ago

Description : A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4141

Published : April 30, 2025, 10:15 p.m. | 1 hour, 31 minutes ago

Description : A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. This affects the function sub_3C03C. The manipulation of the argument host leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-4142

Published : April 30, 2025, 11:16 p.m. | 30 minutes ago

Description : A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. This vulnerability affects the function sub_3C8EC. The manipulation of the argument host leads to buffer overflow. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-3599

Published : April 30, 2025, 5:15 p.m. | 1 hour, 53 minutes ago

Description : Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.

Severity: 6.5 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-3859

Published : April 30, 2025, 5:15 p.m. | 1 hour, 53 minutes ago

Description : Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage This vulnerability affects Focus
Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-21416

Published : April 30, 2025, 6:15 p.m. | 54 minutes ago

Description : Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-24091

Published : April 30, 2025, 6:15 p.m. | 54 minutes ago

Description : An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-30392

Published : April 30, 2025, 6:15 p.m. | 1 hour, 28 minutes ago

Description : Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-30391

Published : April 30, 2025, 6:15 p.m. | 1 hour, 28 minutes ago

Description : Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-30390

Published : April 30, 2025, 6:15 p.m. | 1 hour, 28 minutes ago

Description : Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

Severity: 9.9 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-30389

Published : April 30, 2025, 6:15 p.m. | 1 hour, 28 minutes ago

Description : Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-2156

Published : April 30, 2025, 6:15 p.m. | 53 minutes ago

Description : Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-33074

Published : April 30, 2025, 6:15 p.m. | 53 minutes ago

Description : Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-3269

Published : April 30, 2025, 6:15 p.m. | 53 minutes ago

Description : Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-44193

Published : April 30, 2025, 6:15 p.m. | 53 minutes ago

Description : SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…