3

CVSS3.1

CVE-2025-30343 -

A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or …

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 21, 2025, 2:01 p.m.

5.4

CVSS3.1

CVE-2025-30342 -

An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly enco…

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 21, 2025, 3:03 p.m.

3.5

CVSS3.1

CVE-2025-30345 -

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded properly, but not when del…

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 21, 2025, 3:04 p.m.

5.3

CVSS3.1

CVE-2025-30344 -

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 21, 2025, 3:08 p.m.

4

CVSS3.1

CVE-2025-30347 -

Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 2:19 p.m.

5.8

CVSS3.1

CVE-2025-30348 -

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 2:08 p.m.

5.4

CVSS3.1

CVE-2025-30346 - varnish: Client-Side Desynchronization in Varnish Cache

Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 2:47 p.m.

7.4

CVSS3.1

CVE-2024-53348 -

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 6:15 p.m.

7.4

CVSS3.1

CVE-2024-53349 -

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster

πŸ“… Published: March 21, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 6:15 p.m.

7.8

CVSS3.1

CVE-2024-44305 -

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.

πŸ“… Published: March 20, 2025, 11:53 p.m. πŸ”„ Last Modified: March 24, 2025, 3:10 p.m.
Total resulsts: 286551
Page 41 of 28,656
Β« previous page Β» next page
Filters