4

CVSS3.1

CVE-2025-31335 - opensaml-core: Signature Forgery in OpenSAML

The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-58128 -

In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: July 8, 2025, 5:31 p.m.

9.8

CVSS3.1

CVE-2025-28087 -

Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:22 p.m.

6.3

CVSS3.1

CVE-2025-28093 -

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:11 p.m.

7.5

CVSS3.1

CVE-2024-48615 - libarchive: Null Pointer Dereference in Libarchive

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 2:36 p.m.

7.5

CVSS3.1

CVE-2025-28221 -

Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 5:38 p.m.

9.8

CVSS3.1

CVE-2025-22953 -

A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malic…

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 3:16 p.m.

6.5

CVSS3.1

CVE-2025-28094 -

shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:09 p.m.

7.2

CVSS3.1

CVE-2024-58130 -

In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: July 15, 2025, 6:49 p.m.

6.5

CVSS3.1

CVE-2025-31092 - WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.4 - Cross Site Script…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4.

πŸ“… Published: March 27, 2025, 11:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.
Total resulsts: 347394
Page 5980 of 34,740
Β« previous page Β» next page
Filters