7.2

CVSS3.1

CVE-2024-55904 - IBM DevOps Deploy / IBM UrbanCode Deploy command injection

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted…

πŸ“… Published: Feb. 14, 2025, 3:23 a.m. πŸ”„ Last Modified: Aug. 18, 2025, 6:14 p.m.

5.5

CVSS3.1

CVE-2024-10404 - Clear text password seen in switch-asset-collectors-mw in Brocade SANnav supportsave

CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could allow an authenticated, local attacker to view Brocade Fabric OS switch sensitive information in clear text. An attacker with administrative privileges could retrieve sensitive…

πŸ“… Published: Feb. 14, 2025, 3:13 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 8:02 p.m.

4.5

CVSS3.1

CVE-2025-26791 - dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 8:56 p.m.

8.8

CVSS3.1

CVE-2025-25745 -

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetQuickVPNSettings module.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 5:53 p.m.

5.5

CVSS3.1

CVE-2025-25740 -

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter in the SetQuickVPNSettings module.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 5:53 p.m.

9.8

CVSS3.1

CVE-2024-56973 -

Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: Feb. 28, 2025, 5:15 p.m.

8.4

CVSS3.1

CVE-2025-26788 -

StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: Feb. 15, 2025, 6:30 p.m.

5.1

CVSS3.1

CVE-2025-25991 -

SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 1:48 a.m.

5.4

CVSS3.1

CVE-2024-57790 -

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically proximate attackers to gain root access via UART or SSH.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:15 p.m.

5.9

CVSS3.1

CVE-2025-26157 -

A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 5:58 p.m.
Total resulsts: 343749
Page 6191 of 34,375
Β« previous page Β» next page
Filters