8.6

CVSS3.1

CVE-2024-37358 - Apache James: denial of service through the use of IMAP literals

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7.6 and 3.8.2 restrict such illegitimate …

πŸ“… Published: Feb. 6, 2025, 11:22 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:43 p.m.

6.5

CVSS3.1

CVE-2024-45626 - Apache James: denial of service through JMAP HTML to text conversion

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue.

πŸ“… Published: Feb. 6, 2025, 11:21 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 7:51 p.m.

6.5

CVSS3.1

CVE-2025-0859 - Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitr…

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to …

πŸ“… Published: Feb. 6, 2025, 9:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

5.5

CVSS3.1

CVE-2025-24845 -

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause …

πŸ“… Published: Feb. 6, 2025, 7:06 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 9:05 p.m.

5.5

CVSS3.1

CVE-2025-24483 -

NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, ca…

πŸ“… Published: Feb. 6, 2025, 7:05 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 9:07 p.m.

8.8

CVSS3.0

CVE-2025-23236 -

Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained.

πŸ“… Published: Feb. 6, 2025, 7:05 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:16 p.m.

8.8

CVSS3.0

CVE-2025-20094 -

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.

πŸ“… Published: Feb. 6, 2025, 7:05 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:24 p.m.

8.8

CVSS3.1

CVE-2025-22894 -

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a r…

πŸ“… Published: Feb. 6, 2025, 7:05 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:21 p.m.

8.8

CVSS3.1

CVE-2025-22890 -

Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege of the Windows system where the product is running may be obtained.

πŸ“… Published: Feb. 6, 2025, 7:05 a.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:24 p.m.

7.3

CVSS3.1

CVE-2024-13487 - CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via…

The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution via the get_products_price() function in all versions up to, and including, 2.2.5. This is due to the softwar…

πŸ“… Published: Feb. 6, 2025, 6:53 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.
Total resulsts: 343947
Page 6307 of 34,395
Β« previous page Β» next page
Filters