5.5

CVSS3.1

CVE-2024-41750 - IBM SmartCloud Analytics - Log Analysis security bypass

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

πŸ“… Published: July 23, 2025, 11:15 a.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:29 a.m.

7

CVSS4.0

CVE-2025-54296 - Extension - mooj.org - Stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla

A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.

πŸ“… Published: July 23, 2025, 11:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-40682 - IBM SmartCloud Analytics - Log Analysis denial of service

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.

πŸ“… Published: July 23, 2025, 11:14 a.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:27 p.m.

8.5

CVSS4.0

CVE-2025-50127 - Extension - dj-extensions.com - SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla

A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

πŸ“… Published: July 23, 2025, 11:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-40686 - IBM SmartCloud Analytics - Log Analysis HOST header injection

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross…

πŸ“… Published: July 23, 2025, 11:12 a.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:28 a.m.

5.5

CVSS3.1

CVE-2024-41751 - IBM SmartCloud Analytics - Log Analysis security bypass

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

πŸ“… Published: July 23, 2025, 11:09 a.m. πŸ”„ Last Modified: Aug. 18, 2025, 1:29 a.m.

6.4

CVSS3.1

CVE-2025-27930 - Stored XSS

Zohocorp ManageEngine Applications Manager versionsΒ 176600 and prior are vulnerable to stored cross-site scripting in theΒ File/Directory monitor.

πŸ“… Published: July 23, 2025, 10:20 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

4.8

CVSS4.0

CVE-2025-53882 - The logrotate configuration in the python-mailman of openSUSE allows the mailman user to sent SIGHU…

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes.Β This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.

πŸ“… Published: July 23, 2025, 9:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-41687 - Weidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management API

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.

πŸ“… Published: July 23, 2025, 8:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-41684 - Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).

πŸ“… Published: July 23, 2025, 8:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4539 of 34,919
Β« previous page Β» next page
Filters