4.8

CVSS3.1

CVE-2024-51945 - Stored XSS issues in Server Admin API

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:38 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51944 - Stored XSS in Rest Services Directory

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:38 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-51942 - Stored XSS vulnerability in Rest Admin API under Hosted Feature Services page

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:37 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-10904 - Stored XSS in Server Admin API

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:37 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

4.8

CVSS3.1

CVE-2024-5888 - Stored XSS in Rest Services API for a Toolbox published as GP Service

There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remote, authenticated attacker to create a stored crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. The privileges required …

📅 Published: March 3, 2025, 7:36 p.m. 🔄 Last Modified: April 10, 2025, 8:15 p.m.

2.4

CVSS4.0

CVE-2025-1879 - i-Drive i11/i12 APK hard-coded credentials

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the physical device. It was not possible to identi…

📅 Published: March 3, 2025, 7:31 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

2.3

CVSS4.0

CVE-2025-1878 - i-Drive i11/i12 WiFi default password

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component WiFi. The manipulation leads to use of default password. Access to the local network is required for this attack to succeed. The complexity of…

📅 Published: March 3, 2025, 7 p.m. 🔄 Last Modified: March 6, 2025, 12:21 p.m.

5.3

CVSS4.0

CVE-2025-1889 - picklescan - Security scanning bypass via non-standard file extensions

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not cons…

📅 Published: March 3, 2025, 6:38 p.m. 🔄 Last Modified: Dec. 29, 2025, 3:16 p.m.

8.6

CVSS3.1

CVE-2025-27501 - Server Side Request Forgery in Ziti Console

OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint accepts a user-supplied URL parameter to connect to an OpenZiti Controller and performs a server-side reques…

📅 Published: March 3, 2025, 6:33 p.m. 🔄 Last Modified: April 23, 2025, 6:45 p.m.

7.1

CVSS4.0

CVE-2025-1877 - D-Link DAP-1562 HTTP POST Request pure_auth_check null pointer dereference

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the argument a1 leads to null pointer dereference. It is possible to initiate the attack remotely. The expl…

📅 Published: March 3, 2025, 6:31 p.m. 🔄 Last Modified: March 6, 2025, 12:21 p.m.
Total resulsts: 349182
Page 6472 of 34,919
« previous page » next page
Filters