6.7

CVSS3.1

CVE-2024-45777 - Grub2: grub-core/gettext: integer overflow leads to heap oob write.

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the …

πŸ“… Published: Feb. 18, 2025, 6 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:02 p.m.

1.3

CVSS4.0

CVE-2025-25300 - smartbanner.js rel noopener XSS vulnerability

smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile third parties to abuse `window.opener`, e.g. by redirection or injection on the o…

πŸ“… Published: Feb. 18, 2025, 5:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-26620 - Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credenti…

Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens using the client credentials flow. Concurrent requests to obtain an access token using differing protocol …

πŸ“… Published: Feb. 18, 2025, 5:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.8

CVSS3.1

CVE-2024-4028 - Keycloak-core: stored xss in keycloak when creating a items in admin console

A vulnerability was found in Keycloak. This issue may allow a privileged attacker to use a malicious payload as the permission while creating items (Resource and Permissions) from the admin console, leading to a stored cross-site scripting (XSS) attack.

πŸ“… Published: Feb. 18, 2025, 5:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-49589 - Foundry artifacts denial of service

Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size).

πŸ“… Published: Feb. 18, 2025, 5:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS4.0

CVE-2025-22207 - [20250201] - Core - SQL injection vulnerability in Scheduled Tasks component

Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

πŸ“… Published: Feb. 18, 2025, 4:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-13689 - Uncode Core <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_me…

The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenti…

πŸ“… Published: Feb. 18, 2025, 2:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-1269 - Open Redirect in HAVELSAN's Open Source Project Liman MYS

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.

πŸ“… Published: Feb. 18, 2025, 1:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-1414 - Memory safety bugs fixed in Firefox 135.0.1

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 135.0.1.

πŸ“… Published: Feb. 18, 2025, 1:39 p.m. πŸ”„ Last Modified: April 20, 2026, 6:30 p.m.

5.7

CVSS3.1

CVE-2025-1035 - Path Traversal in Komtera Technolgies' KLog Server

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

πŸ“… Published: Feb. 18, 2025, 11:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6699 of 34,919
Β« previous page Β» next page
Filters