Return to the home page
31 new CVEs published on 2025-04-15 (CVSS: 7.1 - 9.9)

31 new CVEs published on 2025-04-15 (CVSS: 7.1 - 9.9)

CybersecurityVulnerabilitiesExploitsSoftwareSecurity

CVE IDCVSSDescription
CVE-2025-309859.8Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.
CVE-2025-247979.4Meshtastic is an open source mesh networking solution.

A fault in the handling of mesh packets containing invalid protobuf data can result in an attack.

CVE-2025-314918.6AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to the fix, an issue allowed unauthorized access to certain features.
CVE-2025-329297.5Missing Authorization vulnerability in Dmitry V.

(CEO of "UKR Solution") Barcode Generator for WooCommerce allows Exploiting Incorrectly Configured Access Control.

CVE-2025-329319.1DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specially crafted payload.
CVE-2025-267418.8Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates allows Privilege Escalation.

This issue affects Email Notifications for Updates: from n/a through 1.5.

CVE-2025-269598.8Missing Authorization vulnerability in Quý Lê 91 Administrator Z allows Privilege Escalation. This issue affects Administrator Z: from n/a through 2025.
CVE-2025-17829.9In HylaFAX Enterprise Web Interface and AvantFAX,

the language form element is not properly sanitized before being used and can be misused to include malicious code.

CVE-2025-21608.1Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup.
CVE-2025-21617.1Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup.
CVE-2025-267437.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Query Search Filter allows Reflected XSS.

target="_blank" rel="noopener noreferrer">CVE-2025-31490

7.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to the fix, an issue allowed unauthorized access to certain features.
CVE-2025-268897.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound hockeydata LOS allows remote attackers to include arbitrary files.
CVE-2025-268947.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Coming Soon,

Maintenance Mode & Under Construction allows remote attackers to include arbitrary files.

CVE-2025-329147.4A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read. This flaw allows a malicious user to cause a denial of service or possibly execute arbitrary code.