5.7

CVSS4.0

CVE-2025-25184 - Possible Log Injection in Rack::CommonLogger

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content …

📅 Published: Feb. 12, 2025, 4:20 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:18 p.m.

4.1

CVSS3.1

CVE-2024-11628 - Prototype Pollution in Progress® Telerik® Kendo UI for Vue

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

📅 Published: Feb. 12, 2025, 4:17 p.m. 🔄 Last Modified: June 27, 2025, 7:18 p.m.

9.4

CVSS3.1

CVE-2025-25182 - Stroom Authentication/Authorization Bypass when using AWS ALB

Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the applicati…

📅 Published: Feb. 12, 2025, 4:16 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

0.0

CVE-2025-1256 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: Feb. 12, 2025, 4:02 p.m. 🔄 Last Modified: Nov. 14, 2025, 10:19 p.m.

5.1

CVSS4.0

CVE-2025-1208 - code-projects Wazifa System Profile.php cross site scripting

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

📅 Published: Feb. 12, 2025, 4 p.m. 🔄 Last Modified: Feb. 21, 2025, 12:03 p.m.

8.3

CVSS3.1

CVE-2024-11343 - Telerik Document Processing Path Traversal

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.

📅 Published: Feb. 12, 2025, 3:46 p.m. 🔄 Last Modified: Feb. 20, 2025, 8:39 p.m.

4.1

CVSS3.1

CVE-2024-12629 - Prototype Pollution in Progress® Telerik® KendoReact

In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

📅 Published: Feb. 12, 2025, 3:37 p.m. 🔄 Last Modified: June 27, 2025, 5:24 p.m.

2.3

CVSS4.0

CVE-2025-1207 - phjounin TFTPD64 DNS denial of service

A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather hig…

📅 Published: Feb. 12, 2025, 3:31 p.m. 🔄 Last Modified: Feb. 12, 2025, 4:15 p.m.

4.3

CVSS3.1

CVE-2024-9870 - Unintended Proxy or Intermediary ('Confused Deputy') in GitLab

An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.

📅 Published: Feb. 12, 2025, 3:31 p.m. 🔄 Last Modified: Aug. 6, 2025, 6:48 p.m.

4.3

CVSS3.1

CVE-2025-0516 - Incorrect Authorization in GitLab

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

📅 Published: Feb. 12, 2025, 3:30 p.m. 🔄 Last Modified: Aug. 6, 2025, 6:49 p.m.
Total resulsts: 344059
Page 6247 of 34,406
« previous page » next page
Filters