4.6

CVSS3.1

CVE-2025-2901 - org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console

This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: June 20, 2025, 12:15 p.m.

9.8

CVSS3.1

CVE-2025-28219 -

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 3:41 p.m.

9.1

CVSS3.1

CVE-2025-28089 -

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:20 p.m.

5.5

CVSS3.1

CVE-2024-58129 -

In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: July 8, 2025, 5:30 p.m.

5.4

CVSS3.1

CVE-2025-28254 -

Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary code and obtain sensitive information via the first name field in processMentions().

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:42 p.m.

6.3

CVSS3.1

CVE-2025-28092 -

ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:12 p.m.

7.5

CVSS3.1

CVE-2024-57083 - redoc: Prototype Pollution in redoc

A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 5:02 p.m.

9.8

CVSS3.1

CVE-2024-38988 -

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 4:58 p.m.

9.8

CVSS3.1

CVE-2024-56975 -

InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 4:50 p.m.

9.8

CVSS3.1

CVE-2024-24292 -

A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 1:56 p.m.
Total resulsts: 349182
Page 6158 of 34,919
ยซ previous page ยป next page
Filters