6.1

CVSS3.1

CVE-2025-23001 -

A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE: the Supplier's posi…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Feb. 21, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-21674 - net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel Attempt to enable IPsec packet offload in tunnel mode in debug kernel generates the following kernel panic, which is happening due to two issues: 1. In SA ad…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

9.8

CVSS3.1

CVE-2025-22957 -

A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitive information.

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 3:37 p.m.

6.1

CVSS3.1

CVE-2024-42671 -

A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities.

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-21679 - btrfs: add the missing error handling inside get_canonical_dev_path

In the Linux kernel, the following vulnerability has been resolved: btrfs: add the missing error handling inside get_canonical_dev_path Inside function get_canonical_dev_path(), we call d_path() to get the final device path. But d_path() can return error, and in that case the next strscpy() call…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 1:39 p.m.

5.5

CVSS3.1

CVE-2025-21675 - net/mlx5: Clear port select structure when fail to create

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select structure on error so no stale values left after definers are destroyed. That's because the mlx5_lag_destroy_definers() always try to destroy all lag…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

5.5

CVSS3.1

CVE-2025-21677 - pfcp: Destroy device along with udp socket's netns dismantle.

In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is created. Even when net is removed, the device stays alive on de…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 1:41 p.m.

7.5

CVSS3.1

CVE-2024-53357 -

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealiasroute; (4) delete users via the /api/user/…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: May 24, 2025, 1:15 a.m.

9.8

CVSS3.1

CVE-2024-47857 -

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts …

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 8:15 p.m.

9.8

CVSS3.1

CVE-2024-53584 -

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 3:57 p.m.
Total resulsts: 343194
Page 6300 of 34,320
Β« previous page Β» next page
Filters