5.3

CVSS3.1

CVE-2024-57685 -

An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 4:34 p.m.

5.3

CVSS3.1

CVE-2025-26803 -

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:07 a.m.

5.7

CVSS3.1

CVE-2025-25208 - Rhcl: authorino denial of service through authpolicy with sharedsecretref severity

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 26, 2026, 9:27 p.m.

10

CVSS3.1

CVE-2025-27364 -

In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web re…

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: June 20, 2025, 3:42 p.m.

7.2

CVSS3.1

CVE-2025-26200 -

SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: May 1, 2025, 4:52 p.m.

6

CVSS3.1

CVE-2025-23017 -

WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: Feb. 24, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-53544 -

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: Feb. 25, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-54820 -

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: Feb. 24, 2025, 6:15 p.m.

5.7

CVSS3.1

CVE-2025-25209 - Rhcl: sharedsecretref can be used to leak secrets severity

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those…

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 26, 2026, 9:27 p.m.

9.1

CVSS3.1

CVE-2025-26201 -

Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: Feb. 24, 2025, 6:15 p.m.
Total resulsts: 344126
Page 6148 of 34,413
Β« previous page Β» next page
Filters