8.8

CVSS3.1

CVE-2023-51302 -

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:19 p.m.

7.8

CVSS3.1

CVE-2025-25943 -

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 2:02 p.m.

7.1

CVSS3.1

CVE-2024-57262 -

In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:23 a.m.

9.1

CVSS3.1

CVE-2020-35546 -

Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: Feb. 20, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2023-46271 -

Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: Feb. 20, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2023-51301 -

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 7:16 p.m.

6.1

CVSS3.1

CVE-2023-51303 -

PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 7:16 p.m.

8.1

CVSS3.1

CVE-2020-10095 -

Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

πŸ“… Published: Feb. 19, 2025, midnight πŸ”„ Last Modified: Feb. 20, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-13508 - Booking Package <= 1.6.72 - Reflected Cross-Site Scripting via Locale Parameter

The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Feb. 18, 2025, 11:22 p.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

6.8

CVSS4.0

CVE-2025-26624 - Local Privilege Escalation in Rufus 4.6 and previous versions

Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 and earlier versions allows an attacker loading and executing a malicious DLL with escalated privileges (since the executable has been granted higher privileges during the time…

πŸ“… Published: Feb. 18, 2025, 10:40 p.m. πŸ”„ Last Modified: Feb. 19, 2025, 3:02 p.m.
Total resulsts: 343942
Page 6169 of 34,395
Β« previous page Β» next page
Filters