5.5

CVSS3.1

CVE-2024-45673 - IBM Security Verify Bridge information disclosure

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.

πŸ“… Published: Feb. 21, 2025, 4:45 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 10:15 p.m.

6.9

CVSS4.0

CVE-2025-1546 - BDCOM Behavior Management and Auditing System operate.mds log_operate_clear os command injection

A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command inj…

πŸ“… Published: Feb. 21, 2025, 4:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1544 - dingfanzu CMS loadShopInfo.php sql injection

A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. Affected is an unknown function of the file /ajax/loadShopInfo.php. The manipulation of the argument shopId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclo…

πŸ“… Published: Feb. 21, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1543 - iteachyou Dreamer CMS ueditor-1.4.3.3 path traversal

A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3. This issue affects some unknown processing of the file /resource/js/ueditor-1.4.3.3. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to…

πŸ“… Published: Feb. 21, 2025, 4 p.m. πŸ”„ Last Modified: April 4, 2025, 4:36 p.m.

8.7

CVSS4.0

CVE-2025-1539 - D-Link DAP-1320 storagein.pd-XXXXXX replace_special_char stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. Affected by this issue is the function replace_special_char of the file /storagein.pd-XXXXXX. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been d…

πŸ“… Published: Feb. 21, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:42 p.m.

8.7

CVSS4.0

CVE-2025-1538 - D-Link DAP-1320 api set_ws_action heap-based overflow

A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: Feb. 21, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 8:54 p.m.

5.3

CVSS4.0

CVE-2025-1537 - Harpia DiagSystem atualatendimento_jpeg.php sql injection

A vulnerability was found in Harpia DiagSystem 12. It has been rated as critical. This issue affects some unknown processing of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument codexame leads to sql injection. The attack may be initiated remotely. The exploit ha…

πŸ“… Published: Feb. 21, 2025, 2:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1536 - Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command inje…

A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os…

πŸ“… Published: Feb. 21, 2025, 2:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-0838 - Heap Buffer overflow in Abseil

There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass a very large size that would cause an integ…

πŸ“… Published: Feb. 21, 2025, 2:20 p.m. πŸ”„ Last Modified: July 30, 2025, 6:10 p.m.

6.4

CVSS3.1

CVE-2024-10222 - SVG Support <= 2.5.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to …

πŸ“… Published: Feb. 21, 2025, 1:41 p.m. πŸ”„ Last Modified: April 8, 2026, 4:54 p.m.
Total resulsts: 349182
Page 6663 of 34,919
Β« previous page Β» next page
Filters