5.4

CVSS3.1

CVE-2025-0054 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java

SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser…

πŸ“… Published: Feb. 11, 2025, 12:32 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

6.9

CVSS4.0

CVE-2025-1165 - Lumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been di…

πŸ“… Published: Feb. 11, 2025, 12:31 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2025-1164 - code-projects Police FIR Record Management System Add Record stack-based overflow

A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer overflow. Local access is required to approach …

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: April 11, 2025, 6:33 p.m.

6.5

CVSS3.1

CVE-2022-37660 - hostapd: Public Key Exchange (PKEX) Reuse Vulnerability in hostapd

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encr…

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:15 p.m.

3.8

CVSS3.1

CVE-2024-51324 -

An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 10:15 p.m.

5.1

CVSS3.1

CVE-2022-35202 -

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Authn requests. The underlying issue is a Java keystore that may become accessible and downloadable via WebDAV. This keystor…

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

7.9

CVSS3.1

CVE-2024-33469 -

An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: Feb. 13, 2025, 3:15 p.m.

6.8

CVSS3.1

CVE-2024-54916 -

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-54772 -

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with …

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: June 30, 2025, 2:48 p.m.

6.5

CVSS3.1

CVE-2024-57241 -

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

πŸ“… Published: Feb. 11, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 6:03 p.m.
Total resulsts: 343183
Page 6203 of 34,319
Β« previous page Β» next page
Filters