0.0

CVE-2024-38988 -

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2024-38985 -

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2025-28256 -

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2024-56975 -

InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2025-28254 -

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2025-22953 -

A SQL injection vulnerability exists in the Epicor HCM 2021 1.9, specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads into the filter parameter, enabling the unauthorized execution of arbitrary SQL commaโ€ฆ

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2024-24292 -

A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 9:15 p.m.

0.0

CVE-2025-28220 -

Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 6:11 p.m.

0.0

CVE-2025-28219 -

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 6:11 p.m.

0.0

CVE-2024-48615 -

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 6:11 p.m.
Total resulsts: 287371
Page 21 of 28,738
ยซ previous page ยป next page
Filters