5.3

CVSS4.0

CVE-2024-10207 - Server-Side Request Forgery (authenticated) in APROL Web Portal

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs.

πŸ“… Published: March 25, 2025, 4:42 a.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.9

CVSS4.0

CVE-2024-10206 - Server-Side Request Forgery (unauthenticated) in APROL Web Portal

A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.

πŸ“… Published: March 25, 2025, 4:33 a.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.8

CVSS4.0

CVE-2024-8315 - Improper Handling of Insufficient Permissions or Privileges in B&R APROL

An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information.

πŸ“… Published: March 25, 2025, 4:31 a.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

6.9

CVSS4.0

CVE-2025-2734 - PHPGurukul Old Age Home Management System aboutus.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit…

πŸ“… Published: March 25, 2025, 4:31 a.m. πŸ”„ Last Modified: May 15, 2025, 7:38 p.m.

5.3

CVSS4.0

CVE-2025-2733 - mannaandpoem OpenManus Prompt python_execute.py os command injection

A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown part of the file app/tool/python_execute.py of the component Prompt Handler. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The e…

πŸ“… Published: March 25, 2025, 4:31 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.5

CVSS4.0

CVE-2024-8314 - Improper session handling in B&R APROL

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

πŸ“… Published: March 25, 2025, 4:30 a.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

8.7

CVSS4.0

CVE-2024-8313 - Default or Guessable SNMP community names in B&R APROL

An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP.

πŸ“… Published: March 25, 2025, 4:29 a.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

8.6

CVSS4.0

CVE-2025-2732 - H3C Magic BE18000 HTTP POST Request getWifiNeighbour command injection

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipu…

πŸ“… Published: March 25, 2025, 4 a.m. πŸ”„ Last Modified: April 11, 2025, 8:15 p.m.

8.6

CVSS4.0

CVE-2025-2731 - H3C Magic BE18000 HTTP POST Request getDualbandSync command injection

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. Th…

πŸ“… Published: March 25, 2025, 3:31 a.m. πŸ”„ Last Modified: April 11, 2025, 8:15 p.m.

8.6

CVSS4.0

CVE-2025-2730 - H3C Magic BE18000 HTTP POST Request getssidname command injection

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to comma…

πŸ“… Published: March 25, 2025, 3 a.m. πŸ”„ Last Modified: April 11, 2025, 8:15 p.m.
Total resulsts: 342251
Page 5533 of 34,226
Β« previous page Β» next page
Filters