5.1

CVSS4.0

CVE-2025-1209 - code-projects Wazifa System search_resualts.php searchuser cross site scripting

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exp…

📅 Published: Feb. 12, 2025, 4:31 p.m. 🔄 Last Modified: Feb. 19, 2025, 7:04 p.m.

7.1

CVSS3.1

CVE-2024-11629 - Telerik Document Processing RTF Export of Arbitrary File Path

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

📅 Published: Feb. 12, 2025, 4:21 p.m. 🔄 Last Modified: Feb. 19, 2025, 7:09 p.m.

5.7

CVSS4.0

CVE-2025-25184 - Possible Log Injection in Rack::CommonLogger

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content …

📅 Published: Feb. 12, 2025, 4:20 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:18 p.m.

4.1

CVSS3.1

CVE-2024-11628 - Prototype Pollution in Progress® Telerik® Kendo UI for Vue

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

📅 Published: Feb. 12, 2025, 4:17 p.m. 🔄 Last Modified: June 27, 2025, 7:18 p.m.

9.4

CVSS3.1

CVE-2025-25182 - Stroom Authentication/Authorization Bypass when using AWS ALB

Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the applicati…

📅 Published: Feb. 12, 2025, 4:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-1256 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: Feb. 12, 2025, 4:02 p.m. 🔄 Last Modified: Nov. 14, 2025, 10:19 p.m.

5.1

CVSS4.0

CVE-2025-1208 - code-projects Wazifa System Profile.php cross site scripting

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /Profile.php. The manipulation of the argument postcontent leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

📅 Published: Feb. 12, 2025, 4 p.m. 🔄 Last Modified: Feb. 21, 2025, 12:03 p.m.

8.3

CVSS3.1

CVE-2024-11343 - Telerik Document Processing Path Traversal

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.

📅 Published: Feb. 12, 2025, 3:46 p.m. 🔄 Last Modified: Feb. 20, 2025, 8:39 p.m.

4.1

CVSS3.1

CVE-2024-12629 - Prototype Pollution in Progress® Telerik® KendoReact

In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

📅 Published: Feb. 12, 2025, 3:37 p.m. 🔄 Last Modified: June 27, 2025, 5:24 p.m.

2.3

CVSS4.0

CVE-2025-1207 - phjounin TFTPD64 DNS denial of service

A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather hig…

📅 Published: Feb. 12, 2025, 3:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6759 of 34,919
« previous page » next page
Filters