7.3

CVSS3.1

CVE-2025-23094 -

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager V11 R0.22.0 through V11 R0.22.1, V10 R1.54.0 through V10 R1.54.1, and V10 R1.42.6 and earlier could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A success…

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-57609 -

An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-48589 -

Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code via the rol parameter in index.php

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-57610 -

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended …

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 7:07 p.m.

5.4

CVSS3.1

CVE-2024-57429 -

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:13 a.m.

8.1

CVSS3.1

CVE-2024-36553 -

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-57599 -

Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 1:16 a.m.

9.8

CVSS3.1

CVE-2022-40916 -

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:40 p.m.

9.8

CVSS3.1

CVE-2024-57430 -

An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:12 a.m.

4.8

CVSS3.1

CVE-2022-40490 -

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:40 p.m.
Total resulsts: 347919
Page 6706 of 34,792
Β« previous page Β» next page
Filters