2.9

CVSS3.1

CVE-2024-28607 -

The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.

📅 Published: March 11, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-25925 -

A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.

📅 Published: March 11, 2025, midnight 🔄 Last Modified: May 21, 2025, 7:27 p.m.

5.4

CVSS3.1

CVE-2024-51322 -

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp components

📅 Published: March 11, 2025, midnight 🔄 Last Modified: June 12, 2025, 7:25 p.m.

7.3

CVSS3.1

CVE-2024-51319 -

A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.

📅 Published: March 11, 2025, midnight 🔄 Last Modified: May 28, 2025, 6:18 p.m.

10

CVSS3.1

CVE-2025-24201 - webkitgtk: out-of-bounds write vulnerability

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Malic…

📅 Published: March 11, 2025, midnight 🔄 Last Modified: April 3, 2026, 11:45 a.m.

7.3

CVSS3.1

CVE-2025-25748 -

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is dispu…

📅 Published: March 11, 2025, midnight 🔄 Last Modified: Jan. 29, 2026, 9:10 p.m.

8.8

CVSS3.1

CVE-2025-1828 - Perl's Crypt::Random module after 1.05 and before 1.56 may use rand() function for cryptographic fu…

Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. If the Provider is not specified and /dev/urandom or an Entropy Gathering Daemon (egd) service is not available Crypt::Random will default to use the insecure C…

📅 Published: March 10, 2025, 11:51 p.m. 🔄 Last Modified: Sept. 29, 2025, 10:40 p.m.

7.5

CVSS3.1

CVE-2025-27610 - Local File Inclusion in Rack::Static

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The vulnerability occurs …

📅 Published: March 10, 2025, 10:19 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:18 p.m.

4.8

CVSS4.0

CVE-2025-0660 - Stored XSS in Folder Function by Rogue Admin

Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as folder names.  The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.8 with vect…

📅 Published: March 10, 2025, 8:57 p.m. 🔄 Last Modified: Sept. 4, 2025, 3:54 p.m.

7.8

CVSS3.1

CVE-2024-56192 -

In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: March 10, 2025, 8:50 p.m. 🔄 Last Modified: Sept. 4, 2025, 5:13 a.m.
Total resulsts: 349182
Page 6399 of 34,919
« previous page » next page
Filters