6.1

CVSS3.1

CVE-2025-29512 -

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.1

CVSS3.1

CVE-2025-29513 -

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28242 -

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28238 -

Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28237 -

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28235 -

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28059 -

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke assoโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.3

CVSS3.1

CVE-2024-46089 -

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28232 -

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

0.0

CVE-2025-28230 -

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.
Total resulsts: 291035
Page 21 of 29,104
ยซ previous page ยป next page
Filters