7.8

CVSS3.1

CVE-2025-24028 - Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text …

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 1:57 a.m.

3.3

CVSS3.1

CVE-2024-55630 - DOM Clobbering leads to temporary DOS in the note viewer in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that…

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 2:10 a.m.

5.3

CVSS4.0

CVE-2025-1113 - taisan tarzan-cms Add Theme admin#themes upload deserialization

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been discl…

📅 Published: Feb. 7, 2025, 9:31 p.m. 🔄 Last Modified: Aug. 21, 2025, 8:29 p.m.

7.5

CVSS3.1

CVE-2025-24366 - Insufficient sanitization of user provided rsync command in SFTPGo

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default commands some optional commands can be activated, one of them being `rsync`. It is disabled in the default configuration and it is limited to the l…

📅 Published: Feb. 7, 2025, 9:16 p.m. 🔄 Last Modified: Feb. 7, 2025, 10:49 p.m.

6.9

CVSS4.0

CVE-2025-24980 - Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.…

📅 Published: Feb. 7, 2025, 7:56 p.m. 🔄 Last Modified: Jan. 16, 2026, 6:16 p.m.

5.3

CVSS4.0

CVE-2021-41528 - Improper authorization related to Import / Export interfaces on RISC Platform

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

📅 Published: Feb. 7, 2025, 7:54 p.m. 🔄 Last Modified: Feb. 7, 2025, 9:18 p.m.

2.3

CVSS4.0

CVE-2021-41527 - 2FA bypass on the RISC Platform

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

📅 Published: Feb. 7, 2025, 7:44 p.m. 🔄 Last Modified: March 13, 2025, 2:15 p.m.

5.3

CVSS4.0

CVE-2025-1106 - CmsEasy database_admin.php restore_action path traversal

A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/restore_action in the library lib/admin/database_admin.php. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed t…

📅 Published: Feb. 7, 2025, 6:31 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

5.3

CVSS4.0

CVE-2025-1105 - SiberianCMS HTTP GET Request flat cross site scripting

A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /app/sae/design/desktop/flat of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. The attack may be launched remo…

📅 Published: Feb. 7, 2025, 6 p.m. 🔄 Last Modified: Nov. 4, 2025, 7:47 p.m.

7.7

CVSS3.1

CVE-2022-26389 - Improper Access Control Vulnerability in ELI Electrocardiograph Devices

An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior;  * ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior;  * ELI 250c/BUR 250c Resting Electrocardiograph:…

📅 Published: Feb. 7, 2025, 5:07 p.m. 🔄 Last Modified: Feb. 7, 2025, 6:49 p.m.
Total resulsts: 343054
Page 6201 of 34,306
« previous page » next page
Filters