4.8

CVSS3.1

CVE-2025-25988 -

Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 1:53 a.m.

4.3

CVSS3.1

CVE-2024-57969 -

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 3 p.m.

5.1

CVSS3.1

CVE-2025-25993 -

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 7:43 p.m.

6.1

CVSS3.1

CVE-2025-25990 -

Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 1:50 a.m.

8.6

CVSS3.1

CVE-2025-26819 -

Monero through 0.18.3.4 before ec74ff4 does not have response limits on HTTP server connections.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: Sept. 30, 2025, 8:18 p.m.

7.5

CVSS3.1

CVE-2025-25997 -

Directory Traversal vulnerability in FeMiner wms v.1.0 allows a remote attacker to obtain sensitive information via the databak.php component.

πŸ“… Published: Feb. 14, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 2:24 p.m.

5.9

CVSS4.0

CVE-2024-12054 - ZF Roll Stability Support Plus (RSSPlus) Authentication Bypass By Primary Weakness

ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment or via pivot from J2497 telematics devices) call diagnostic…

πŸ“… Published: Feb. 13, 2025, 10:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS4.0

CVE-2025-24836 - Qardio Heart Health IOS and Android Application and QardioARM A100 Uncaught Exception

With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician's app to take patient readings and ostensibly flood it with requests,…

πŸ“… Published: Feb. 13, 2025, 9:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-23421 - Qardio iOS and Android applications Files or Directories Accessible to External Parties

An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.

πŸ“… Published: Feb. 13, 2025, 9:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-25195 - Zulip events can leak private channel names

Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received traffic for 180 days. However, upon doing so, an event was sent to all users in the organization, not just users in…

πŸ“… Published: Feb. 13, 2025, 9:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6736 of 34,919
Β« previous page Β» next page
Filters