5.9

CVSS3.1

CVE-2025-2324 - A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a fol…

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.

πŸ“… Published: March 19, 2025, 3:23 p.m. πŸ”„ Last Modified: July 31, 2025, 3:53 p.m.

5.5

CVSS3.1

CVE-2025-23382 -

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure…

πŸ“… Published: March 19, 2025, 3:20 p.m. πŸ”„ Last Modified: May 20, 2025, 6:01 p.m.

8.6

CVSS3.1

CVE-2025-30154 - Multiple Reviewdog actions were compromised during a specific time period

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1…

πŸ“… Published: March 19, 2025, 3:15 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

5.5

CVSS3.1

CVE-2025-26475 -

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing attack exposure, preventing accidental misconfigurations, and ensuring security controls remain active.

πŸ“… Published: March 19, 2025, 3:13 p.m. πŸ”„ Last Modified: May 20, 2025, 6:01 p.m.

2.6

CVSS3.1

CVE-2024-42176 - HCL MyXalytics is affected by concurrent login vulnerability

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.

πŸ“… Published: March 19, 2025, 2:24 p.m. πŸ”„ Last Modified: May 16, 2025, 1:45 p.m.

4.3

CVSS3.1

CVE-2025-1472 - Unauthorized View Access to Site Statistics and Team Statistics

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

πŸ“… Published: March 19, 2025, 2:11 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 6:05 p.m.

9.8

CVSS3.1

CVE-2025-2512 - File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated File Upload via upload Function

The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on t…

πŸ“… Published: March 19, 2025, 11:23 a.m. πŸ”„ Last Modified: Aug. 11, 2025, 2:58 p.m.

4.7

CVSS3.1

CVE-2024-45644 - IBM Security ReaQta file upload

IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

πŸ“… Published: March 19, 2025, 11:16 a.m. πŸ”„ Last Modified: Sept. 1, 2025, 1:03 a.m.

4.9

CVSS3.1

CVE-2025-2511 - AHAthat Plugin <= 1.6 - Authenticated (Administrator+) SQL Injection via id Parameter

The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for au…

πŸ“… Published: March 19, 2025, 11:10 a.m. πŸ”„ Last Modified: March 19, 2025, 1:31 p.m.

8.8

CVSS3.1

CVE-2024-12920 - FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Missing Authorization in Multip…

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settin…

πŸ“… Published: March 19, 2025, 11:10 a.m. πŸ”„ Last Modified: March 19, 2025, 1:33 p.m.
Total resulsts: 342311
Page 5618 of 34,232
Β« previous page Β» next page
Filters