5.3

CVSS3.1

CVE-2025-0584 - aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF)

The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.

πŸ“… Published: Jan. 20, 2025, 2:06 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 7:14 p.m.

2

CVSS4.0

CVE-2024-13524 - obsproject OBS Studio untrusted search path

A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is rathe…

πŸ“… Published: Jan. 20, 2025, 2 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-0583 - aEnrich Technology a+HRD - Reflected Cross-site Scripting(XSS)

The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

πŸ“… Published: Jan. 20, 2025, 1:51 a.m. πŸ”„ Last Modified: Nov. 17, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-0578 - Facile Sistemas Cloud Apps Password Reset forgotpassword cross site scripting

A vulnerability was found in Facile Sistemas Cloud Apps up to 20250107. It has been classified as problematic. Affected is an unknown function of the file /account/forgotpassword of the component Password Reset Handler. The manipulation of the argument reterros leads to cross site scripting. It is …

πŸ“… Published: Jan. 20, 2025, 1 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2023-52923 - netfilter: nf_tables: adapt set backend to use GC transaction API

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: adapt set backend to use GC transaction API Use the GC transaction API to replace the old and buggy gc API and the busy mark approach. No set elements are removed from async garbage collection anymore, inst…

πŸ“… Published: Jan. 20, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 8:03 p.m.

8.4

CVSS3.1

CVE-2025-24337 -

WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.

πŸ“… Published: Jan. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-21655 - io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the io_ev_fd, it calls io_eventfd_free() directly if the refcount d…

πŸ“… Published: Jan. 20, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

5.4

CVSS3.1

CVE-2025-0604 - Keycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in ke…

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD r…

πŸ“… Published: Jan. 20, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-11218 - Podman: buildah: container breakout by using --jobs=2 and a race condition when building a maliciou…

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the h…

πŸ“… Published: Jan. 20, 2025, midnight πŸ”„ Last Modified: April 24, 2026, 11:31 a.m.

6.9

CVSS4.0

CVE-2025-0576 - Mobotix M15 player cross site scripting

A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of the argument p_qual leads to cross site scripting. The attack may be in…

πŸ“… Published: Jan. 19, 2025, 11:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346671
Page 6793 of 34,668
Β« previous page Β» next page
Filters