5.3

CVSS4.0

CVE-2024-48864 - File Station 5

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to read/write files or directories. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4…

πŸ“… Published: March 7, 2025, 4:12 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 5:19 p.m.

2.1

CVSS4.0

CVE-2024-38638 - QTS, QuTS hero

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5.2.x are not affected. We have already fixe…

πŸ“… Published: March 7, 2025, 4:12 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:22 p.m.

5.3

CVSS3.1

CVE-2024-13086 - QTS, QuTS hero

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QTS 5.2.0.2851 build 20240808 and later Q…

πŸ“… Published: March 7, 2025, 4:12 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:54 p.m.

7.5

CVSS3.1

CVE-2025-27604 - XWiki Confluence Migrator Pro's homepage is public

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.

πŸ“… Published: March 7, 2025, 4:11 p.m. πŸ”„ Last Modified: March 13, 2025, 2:40 p.m.

9.1

CVSS3.1

CVE-2025-27603 - XWiki Confluence Migrator Pro allows Remote Code Execution via unescaped translations

XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0.

πŸ“… Published: March 7, 2025, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS4.0

CVE-2025-27597 - Vue I18n Prototype Pollution in `handleFlatJson`

Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the g…

πŸ“… Published: March 7, 2025, 3:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-27518 - Cognita CORS misconfiguration in backend API server

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend server allows arbitrary websites to send cross site requests to the application. This vulnerability is fixe…

πŸ“… Published: March 7, 2025, 3:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-27519 - Cognita Arbitrary File Write

Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at /v1/internal/upload-to-local-directory which is enabled when the Local env variable is set to true, such as when Cognita is setu…

πŸ“… Published: March 7, 2025, 3:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-27152 - Possible SSRF and Credential Leakage via Absolute URL in axios Requests

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impa…

πŸ“… Published: March 7, 2025, 3:13 p.m. πŸ”„ Last Modified: Nov. 25, 2025, 5:58 p.m.

5.1

CVSS4.0

CVE-2025-2090 - PHPGurukul Pre-School Enrollment System Sub Admin add-subadmin.php access control

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php of the component Sub Admin Handler. The manipulation leads to improper access controls. The attack may be lau…

πŸ“… Published: March 7, 2025, 3 p.m. πŸ”„ Last Modified: April 3, 2025, 1:33 p.m.
Total resulsts: 349182
Page 6417 of 34,919
Β« previous page Β» next page
Filters