8

CVSS3.1

CVE-2025-22961 -

A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated attackers can directly access sensitive database backup files (snapshot_users.db) via publicly exposed U…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 12, 2025, 7:15 p.m.

8

CVSS3.1

CVE-2025-22960 -

A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially revealing sensitive session-related information such as session IDs (sess_id) and auth…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:15 p.m.

7.4

CVSS3.1

CVE-2025-21701 - net: avoid race between device unregistration and ethnl ops

In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen if a device is being unregistered while its number of channels are being modified. DEBUG_LOCKS_WARN_ON(lock->magic != lock) WARNING:…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2024-53309 -

A stack-based buffer overflow vulnerability exists in Effectmatrix Total Video Converter Command Line (TVCC) 2.50 when an overly long string is passed to the "-f" parameter. This can lead to memory corruption, potentially allowing arbitrary code execution or causing a denial of service via speciall…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:15 p.m.

6.8

CVSS3.1

CVE-2024-56908 -

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directo…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:15 p.m.

7.2

CVSS3.1

CVE-2025-25354 -

A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Feb. 14, 2025, 7:39 p.m.

6.8

CVSS3.1

CVE-2024-57782 -

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-25389 -

A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 7:04 p.m.

5.4

CVSS3.1

CVE-2024-54951 -

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 9:07 p.m.

7.2

CVSS3.1

CVE-2025-25352 -

A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: Feb. 14, 2025, 7:43 p.m.
Total resulsts: 343923
Page 6221 of 34,393
Β« previous page Β» next page
Filters