5.3

CVSS3.1

CVE-2025-27157 - Mastodon's rate-limits are missing on `/auth/setup`

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are missing on `/auth/setup`. Without those rate limits, an attacker can craft requests that will send an email to an arbitrary addresses. Versions 4.2.16 a…

πŸ“… Published: Feb. 27, 2025, 5:12 p.m. πŸ”„ Last Modified: June 24, 2025, 3:59 p.m.

5.3

CVSS4.0

CVE-2025-1742 - pihome-shc PiHome home.php cross site scripting

A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is some unknown functionality of the file /home.php. The manipulation of the argument page_name leads to cross site scripting. The attack may be launched remotely. The exploit has b…

πŸ“… Published: Feb. 27, 2025, 5 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:31 p.m.

5.3

CVSS4.0

CVE-2024-9285 - Tu Yafeng Via Browser Javascript Bridge cross site scripting

A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disc…

πŸ“… Published: Feb. 27, 2025, 4:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-23687 - WordPress Woo Store Mode plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo Store Mode woo-store-mode allows Reflected XSS.This issue affects Woo Store Mode: from n/a through <= 1.0.1.

πŸ“… Published: Feb. 27, 2025, 4:16 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

3.8

CVSS3.1

CVE-2025-0914 - Velociraptor Shell Plugin Prevent_execve Bypass

An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This setting is not usually rec…

πŸ“… Published: Feb. 27, 2025, 4:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-1741 - b1gMail Admin Page users.php deserialization

A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of the component Admin Page. The manipulation of the argument query/q leads to deserialization. The attack can be launched remot…

πŸ“… Published: Feb. 27, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-1756 - MongoDB Shell may be susceptible to local privilege escalation in Windows

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0

πŸ“… Published: Feb. 27, 2025, 3:28 p.m. πŸ”„ Last Modified: April 9, 2025, 2:07 p.m.

7.5

CVSS3.1

CVE-2025-1755 - MongoDB Compass may be susceptible to local privilege escalation in Windows

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

πŸ“… Published: Feb. 27, 2025, 3:24 p.m. πŸ”„ Last Modified: April 9, 2025, 2:07 p.m.

5.5

CVSS3.1

CVE-2024-54170 - IBM EntireX denial of service

IBM EntireX 11.1Β could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consumes excessive CPU cycles.

πŸ“… Published: Feb. 27, 2025, 2:55 p.m. πŸ”„ Last Modified: July 7, 2025, 5:51 p.m.

6.5

CVSS3.1

CVE-2024-54169 - IBM EntireX path traversal

IBM EntireX 11.1Β could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

πŸ“… Published: Feb. 27, 2025, 2:54 p.m. πŸ”„ Last Modified: July 7, 2025, 5:52 p.m.
Total resulsts: 349182
Page 6521 of 34,919
Β« previous page Β» next page
Filters