4.7

CVSS4.0

CVE-2025-22607 - Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by only knowing the UUID…

πŸ“… Published: Jan. 24, 2025, 3:45 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:12 p.m.

8.5

CVSS4.0

CVE-2025-22606 - Coolify Command Injection Vulnerability in Project Name

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In version 4.0.0-beta.358 and possibly earlier versions, when creating or updating a "project," it is possible to inject arbitrary shell commands by altering the project name. If a name includes unes…

πŸ“… Published: Jan. 24, 2025, 3:38 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:12 p.m.

6.5

CVSS3.1

CVE-2024-45077 - IBM Maximo Asset Management file upload

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.

πŸ“… Published: Jan. 24, 2025, 3:38 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 3:18 p.m.

4.3

CVSS3.1

CVE-2025-23991 - WordPress Product Size Charts Plugin for WooCommerce plugin <= 2.4.5 - Broken Access Control vulner…

Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5.

πŸ“… Published: Jan. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

5.3

CVSS4.0

CVE-2025-0699 - JoeyBling bootplus list sql injection

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can…

πŸ“… Published: Jan. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 7:05 p.m.

5.3

CVSS4.0

CVE-2025-0698 - JoeyBling bootplus list sql injection

A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an unknown function of the file /admin/sys/menu/list. The manipulation of the argument sort/order leads to sql injection. It is possible to launch the atta…

πŸ“… Published: Jan. 24, 2025, 3:31 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 7:05 p.m.

8

CVSS3.1

CVE-2024-40693 - IBM Planning Analytics file upload

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further…

πŸ“… Published: Jan. 24, 2025, 3:26 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:01 p.m.

8

CVSS3.1

CVE-2024-25034 - IBM Planning Analytics file upload

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.

πŸ“… Published: Jan. 24, 2025, 3:25 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:01 p.m.

6.5

CVSS3.1

CVE-2024-13698 - Jobify - Job Board WordPress Theme <= 4.2.7 - Missing Authorization to Unauthenticated Server-Side …

The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and 'generate_image_via_ai' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthent…

πŸ“… Published: Jan. 24, 2025, 3:21 p.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

5.3

CVSS3.1

CVE-2024-40706 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.

πŸ“… Published: Jan. 24, 2025, 3:20 p.m. πŸ”„ Last Modified: March 11, 2025, 5:58 p.m.
Total resulsts: 346717
Page 6730 of 34,672
Β« previous page Β» next page
Filters