5.3

CVSS3.1

CVE-2024-55913 - IBM Concert Software path traversal

IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

πŸ“… Published: May 2, 2025, 12:38 a.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

5.9

CVSS3.1

CVE-2024-55912 - IBM Concert Software information disclosure

IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

πŸ“… Published: May 2, 2025, 12:36 a.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

6.5

CVSS3.1

CVE-2024-55909 - IBM Concert Software denial of service

IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expansion of archive files without controlling resource consumption.

πŸ“… Published: May 2, 2025, 12:35 a.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

6.9

CVSS4.0

CVE-2025-4192 - itsourcecode Restaurant Management System category_save.php sql injection

A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/category_save.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The ex…

πŸ“… Published: May 2, 2025, 12:31 a.m. πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

6.9

CVSS4.0

CVE-2025-4191 - PHPGurukul Employee Record Management System editmyeducation.php sql injection

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /editmyeducation.php. The manipulation of the argument coursepg leads to sql injection. The attack can be launched re…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

5.3

CVSS4.0

CVE-2025-4186 - Wangshen SecGate 3600 g=route_ispinfo_export_save path traversal

A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 2024. Affected is an unknown function of the file /?g=route_ispinfo_export_save. The manipulation of the argument file_name leads to path traversal. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 1:52 p.m.

2.9

CVSS3.1

CVE-2024-58253 -

In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 8:15 p.m.

0.0

CVE-2025-45800 -

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 5:15 p.m.

0.0

CVE-2025-44868 -

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:15 p.m.

0.0

CVE-2025-44877 -

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:15 p.m.
Total resulsts: 292479
Page 21 of 29,248
Β« previous page Β» next page
Filters