5.3

CVSS3.1

CVE-2024-6097 - Absolute Path Traversal Vulnerability

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

📅 Published: Feb. 12, 2025, 5:37 p.m. 🔄 Last Modified: Feb. 24, 2025, 4:31 p.m.

5.1

CVSS4.0

CVE-2025-1213 - pihome-shc PiHome index.php cross site scripting

A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The exploit h…

📅 Published: Feb. 12, 2025, 5:31 p.m. 🔄 Last Modified: Oct. 17, 2025, 3:18 p.m.

0.0

CVE-2025-1258 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: Feb. 12, 2025, 5:22 p.m. 🔄 Last Modified: Feb. 20, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2025-1210 - code-projects Wazifa System control.php sql injection

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been…

📅 Published: Feb. 12, 2025, 5 p.m. 🔄 Last Modified: Feb. 19, 2025, 7:03 p.m.

5.1

CVSS4.0

CVE-2025-1209 - code-projects Wazifa System search_resualts.php searchuser cross site scripting

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exp…

📅 Published: Feb. 12, 2025, 4:31 p.m. 🔄 Last Modified: Feb. 19, 2025, 7:04 p.m.

7.1

CVSS3.1

CVE-2024-11629 - Telerik Document Processing RTF Export of Arbitrary File Path

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

📅 Published: Feb. 12, 2025, 4:21 p.m. 🔄 Last Modified: Feb. 19, 2025, 7:09 p.m.

5.7

CVSS4.0

CVE-2025-25184 - Possible Log Injection in Rack::CommonLogger

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content …

📅 Published: Feb. 12, 2025, 4:20 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:18 p.m.

4.1

CVSS3.1

CVE-2024-11628 - Prototype Pollution in Progress® Telerik® Kendo UI for Vue

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

📅 Published: Feb. 12, 2025, 4:17 p.m. 🔄 Last Modified: June 27, 2025, 7:18 p.m.

9.4

CVSS3.1

CVE-2025-25182 - Stroom Authentication/Authorization Bypass when using AWS ALB

Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the applicati…

📅 Published: Feb. 12, 2025, 4:16 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

0.0

CVE-2025-1256 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: Feb. 12, 2025, 4:02 p.m. 🔄 Last Modified: Nov. 14, 2025, 10:19 p.m.
Total resulsts: 343975
Page 6238 of 34,398
« previous page » next page
Filters