7.5

CVSS3.0

CVE-2024-8550 - Local File Inclusion (LFI) in modelscope/agentscope

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue aris…

📅 Published: Feb. 10, 2025, 6:50 p.m. 🔄 Last Modified: July 30, 2025, 1:02 a.m.

6.1

CVSS3.1

CVE-2024-13010 - WP Foodbakery <= 4.8 - Reflected Cross-Site Scripting

The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on the 'search_type' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web script…

📅 Published: Feb. 10, 2025, 6:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-13011 - WP Foodbakery <= 4.7 - Unauthenticated Arbitrary File Upload

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affec…

📅 Published: Feb. 10, 2025, 6:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-27859 -

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.

📅 Published: Feb. 10, 2025, 6:09 p.m. 🔄 Last Modified: April 2, 2026, 7:17 p.m.

2.3

CVSS4.0

CVE-2025-1152 - GNU Binutils ld xstrdup.c xstrdup memory leak

A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitabil…

📅 Published: Feb. 10, 2025, 6 p.m. 🔄 Last Modified: July 12, 2025, 3:26 p.m.

5.7

CVSS4.0

CVE-2025-25188 - DNSSEC validation may accept broken authentication chains

Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DNSSEC verification in the client library, stub resolver, or recursive resolver. The DNSSEC validation…

📅 Published: Feb. 10, 2025, 5:35 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-1151 - GNU Binutils ld xmemdup.c xmemdup memory leak

A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitat…

📅 Published: Feb. 10, 2025, 5 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

2.3

CVSS4.0

CVE-2025-1150 - GNU Binutils ld libbfd.c bfd_malloc memory leak

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. …

📅 Published: Feb. 10, 2025, 4:31 p.m. 🔄 Last Modified: March 11, 2025, 7:01 p.m.

6.5

CVSS3.1

CVE-2025-25186 - Net::IMAP vulnerable to possible DoS by memory exhaustion

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is co…

📅 Published: Feb. 10, 2025, 3:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-24892 - OpenProject stored HTML injection vulnerability

OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the Group Management section. Groups created with HTML script tags are not properly escaped before rendering them in a projec…

📅 Published: Feb. 10, 2025, 3:46 p.m. 🔄 Last Modified: Aug. 27, 2025, 2:09 a.m.
Total resulsts: 348031
Page 6692 of 34,804
« previous page » next page
Filters