5.4

CVSS3.1

CVE-2024-56882 -

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kurstitel and Kurzinfo input fields. The injected payload is executed for each authenticated user who views and interacts wit…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:42 p.m.

5

CVSS3.1

CVE-2024-57055 -

Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is limited to services used by the client (not the general-use JSON services) and requires reverse engineer…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-57050 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation duplicate of CVE-2018-11714. Notes: All CVE users should reference CVE-2018-11714 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 10:15 p.m.

9.8

CVSS3.1

CVE-2025-25467 -

Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-25891 -

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:46 p.m.

8.8

CVSS3.1

CVE-2024-57046 -

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:11 p.m.

6.5

CVSS3.1

CVE-2025-22919 -

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-45774 - Grub2: reader/jpeg: heap oob write during jpeg parsing

A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive information to bypass secure boot protections is not discarded.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-55460 -

A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2025-25895 -

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:46 p.m.
Total resulsts: 348595
Page 6650 of 34,860
Β« previous page Β» next page
Filters