8.2

CVSS3.1

CVE-2024-9334 - Information Disclosure in E-Kent's Pallium Vehicle Tracking

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass.This issue affects Pallium Vehicle Tracking: before 17.10.2024.

πŸ“… Published: Feb. 27, 2025, 1:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-27154 - Spotipy's cache file, containing spotify auth token, is created with overly broad permissions

Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by default, when it could be locked down to `rw-------` (600) permissions. This leads t…

πŸ“… Published: Feb. 27, 2025, 1:53 p.m. πŸ”„ Last Modified: April 7, 2025, 6:24 p.m.

6.4

CVSS3.1

CVE-2024-13402 - BuddyBoss Platform <= 2.7.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_ti…

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level …

πŸ“… Published: Feb. 27, 2025, 12:47 p.m. πŸ”„ Last Modified: April 8, 2026, 4:48 p.m.

7.1

CVSS3.1

CVE-2025-1739 - Multiple vulnerabilities in Trivision Camera NC227WF

An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activ…

πŸ“… Published: Feb. 27, 2025, 12:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.9

CVSS3.1

CVE-2025-1693 - MongoDB Shell may be susceptible to control character Injection via shell output

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages that appear to originate from mongosh or the underlying ope…

πŸ“… Published: Feb. 27, 2025, 12:39 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:39 p.m.

6.3

CVSS3.1

CVE-2025-1692 - MongoDB Shell may be susceptible to control character injection via pasting

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted text can be used to obfuscate malicious code. This issue affect…

πŸ“… Published: Feb. 27, 2025, 12:37 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:40 p.m.

7.6

CVSS3.1

CVE-2025-1691 - MongoDB Shell may be susceptible to Control Character Injection via autocomplete

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run obfuscated malicious text. This requires user interaction in the form of the user using β€˜tab’ to autocomplete t…

πŸ“… Published: Feb. 27, 2025, 12:34 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 4:42 p.m.

6.2

CVSS3.1

CVE-2025-1738 - Multiple vulnerabilities in Trivision Camera NC227WF

A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity, exposing this sensitive information to a third party.

πŸ“… Published: Feb. 27, 2025, 12:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-1751 - SQL Injection CIGES

A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.

πŸ“… Published: Feb. 27, 2025, 12:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-10918 - Stack-based Buffer Overflow in libmodbus library

Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length.

πŸ“… Published: Feb. 27, 2025, 11:44 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.
Total resulsts: 349182
Page 6523 of 34,919
Β« previous page Β» next page
Filters