9.3

CVSS4.0

CVE-2024-51547 - Credentials Disclosure - keys

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

πŸ“… Published: Feb. 6, 2025, 4:12 a.m. πŸ”„ Last Modified: May 23, 2025, 10:15 a.m.

6.5

CVSS3.1

CVE-2025-0799 - IBM App Connect Enterprise Arbitrary File Write

IBM App Connect enterpriseΒ 12.0.1.0 through 12.0.12.10 andΒ 13.0.1.0 through 13.0.2.1Β could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories.

πŸ“… Published: Feb. 6, 2025, 12:24 a.m. πŸ”„ Last Modified: Aug. 12, 2025, 6:46 p.m.

9.1

CVSS3.1

CVE-2024-51450 - IBM Security Verify Directory Command Execution

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

πŸ“… Published: Feb. 6, 2025, 12:15 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 4:59 p.m.

7.8

CVSS3.1

CVE-2024-49814 - IBM Security Verify Access Appliance Privilege Escalation

IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.

πŸ“… Published: Feb. 6, 2025, 12:10 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 5:02 p.m.

6.6

CVSS3.1

CVE-2024-36557 -

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it …

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-36555 -

Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-number which allows for forging the identity…

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-36554 -

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending an SMS to the device which returns sensitive information.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2024-53586 -

An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing da…

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 11, 2025, 3:15 p.m.

6.3

CVSS3.1

CVE-2024-48589 -

Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 11, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2024-57610 -

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended …

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 7:07 p.m.
Total resulsts: 344126
Page 6326 of 34,413
Β« previous page Β» next page
Filters