4.8

CVSS4.0

CVE-2025-29790 - Contao allows cross-site scripting through SVG uploads

Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.

๐Ÿ“… Published: March 18, 2025, 6:36 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 6:22 p.m.

8.6

CVSS3.1

CVE-2025-24801 - GLPI allows authenticated remote code execution

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.

๐Ÿ“… Published: March 18, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 12:57 a.m.

7.5

CVSS3.1

CVE-2025-24799 - GLPI allows unauthenticated SQL injection through the inventory endpoint

GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

๐Ÿ“… Published: March 18, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:45 p.m.

8.2

CVSS4.0

CVE-2025-21619 - GLPI allows SQL injection through the rules configuration

GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.

๐Ÿ“… Published: March 18, 2025, 6:25 p.m. ๐Ÿ”„ Last Modified: July 31, 2025, 6:48 p.m.

0.0

CVE-2025-2504 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: March 18, 2025, 4:30 p.m. ๐Ÿ”„ Last Modified: July 5, 2025, 11:15 p.m.

9.6

CVSS3.1

CVE-2024-56347 - IBM AIX command execution

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

๐Ÿ“… Published: March 18, 2025, 4:16 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

10

CVSS3.1

CVE-2024-56346 - IBM AIX command execution

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

๐Ÿ“… Published: March 18, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2025-27688 -

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

๐Ÿ“… Published: March 18, 2025, 3:55 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

4.8

CVSS4.0

CVE-2025-2491 - Dromara ujcms Edit Template File Page WebFileTemplateController.java update cross site scripting

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site scripting. It is poโ€ฆ

๐Ÿ“… Published: March 18, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 7:41 p.m.

4.1

CVSS3.1

CVE-2024-49822 - IBM QRadar Advisor server-side request forgery

IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

๐Ÿ“… Published: March 18, 2025, 2:19 p.m. ๐Ÿ”„ Last Modified: Sept. 1, 2025, 1:04 a.m.
Total resulsts: 349182
Page 6310 of 34,919
ยซ previous page ยป next page
Filters