4.7

CVSS3.1

CVE-2024-22880 -

Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary code via a crafted script to the webchat component.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 8:29 p.m.

6.1

CVSS3.1

CVE-2024-28803 -

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-29360 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

7.5

CVSS3.1

CVE-2025-29359 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

7.5

CVSS3.1

CVE-2025-29357 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at /goform/SetPptpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

6.1

CVSS3.1

CVE-2024-55060 -

A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:30 p.m.

6.5

CVSS3.1

CVE-2025-25363 -

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload i…

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:43 p.m.

5.3

CVSS3.1

CVE-2025-28015 -

A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 7:49 p.m.

5.4

CVSS3.1

CVE-2025-25625 -

A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML and Javascript on th…

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 6:26 p.m.

6.7

CVSS3.1

CVE-2024-57062 -

An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:43 p.m.
Total resulsts: 349182
Page 6354 of 34,919
Β« previous page Β» next page
Filters