6.1

CVSS3.1

CVE-2024-41503 -

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save option in the "Busca" (search) function.

πŸ“… Published: June 10, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-37394 -

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious s…

πŸ“… Published: June 10, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 9:51 a.m.

6.1

CVSS3.1

CVE-2024-41505 -

Jetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field "Profisso" (professor).

πŸ“… Published: June 10, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:12 p.m.

5.4

CVSS3.1

CVE-2024-57189 -

In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.

πŸ“… Published: June 10, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

9.8

CVSS3.1

CVE-2024-57190 -

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.

πŸ“… Published: June 10, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

3.2

CVSS3.1

CVE-2025-0036 -

In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.

πŸ“… Published: June 9, 2025, 11:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-0037 -

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.

πŸ“… Published: June 9, 2025, 11:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-5903 - TOTOLINK T10 POST Request cstecgi.cgi setWiFiAclRules buffer overflow

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the a…

πŸ“… Published: June 9, 2025, 11:31 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

8.7

CVSS4.0

CVE-2025-5902 - TOTOLINK T10 POST Request cstecgi.cgi setUpgradeFW buffer overflow

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The attack may be initiated …

πŸ“… Published: June 9, 2025, 11 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

9.3

CVSS4.0

CVE-2025-30515 - CyberData 011209 SIP Emergency Intercom Path Traversal

CyberDataΒ 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

πŸ“… Published: June 9, 2025, 10:31 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:21 p.m.
Total resulsts: 349182
Page 5105 of 34,919
Β« previous page Β» next page
Filters