5.4

CVSS3.1

CVE-2024-13237 - File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONT…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.38.

📅 Published: Jan. 9, 2025, 6:15 p.m. 🔄 Last Modified: June 4, 2025, 4:31 p.m.

2.1

CVSS4.0

CVE-2025-22149 - JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh

JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite or append. This is a security issue for use …

📅 Published: Jan. 9, 2025, 5:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-21628 - Chatwoot has a Blind SQL-injection in Conversation and Contacts filters

Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator passed from the frontend or the API. This provided any actor who is authenticated, an attack vector to run arbitrary SQL within the filter query by addin…

📅 Published: Jan. 9, 2025, 5:10 p.m. 🔄 Last Modified: Oct. 29, 2025, 2:52 p.m.

7.1

CVSS4.0

CVE-2025-21600 - Junos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed …

An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS)…

📅 Published: Jan. 9, 2025, 4:49 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:34 p.m.

7.1

CVSS4.0

CVE-2025-21602 - Junos OS and Junos OS Evolved: Receipt of specially crafted BGP update packet causes RPD crash

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause rpd to crash and restart, resulting in a Denial of Service (D…

📅 Published: Jan. 9, 2025, 4:49 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:33 p.m.

8.7

CVSS4.0

CVE-2025-21599 - Junos OS Evolved: Receipt of specifically malformed IPv6 packets causes kernel memory exhaustion le…

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service.  Receipt of specifically malformed IPv6 packets, destined to the device, causes ke…

📅 Published: Jan. 9, 2025, 4:46 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:34 p.m.

6.8

CVSS4.0

CVE-2025-21596 - Junos OS: SRX1500,SRX4100,SRX4200: Execution of low-privileged CLI command results in chassisd crash

An Improper Handling of Exceptional Conditions vulnerability in the command-line processing of Juniper Networks Junos OS on SRX1500, SRX4100, and SRX4200 devices allows a local, low-privileged authenticated attacker executing the 'show chassis environment pem' command to cause the chassis daemon (c…

📅 Published: Jan. 9, 2025, 4:41 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:35 p.m.

7.1

CVSS4.0

CVE-2025-21593 - Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update …

An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SRv6 (Segment Routing over IPv6) enabled,…

📅 Published: Jan. 9, 2025, 4:41 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:36 p.m.

6.8

CVSS4.0

CVE-2025-21592 - Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows a local, low-privileged user with access to the Junos CLI to view the contents of sensitive files on the file system. Through th…

📅 Published: Jan. 9, 2025, 4:39 p.m. 🔄 Last Modified: Jan. 26, 2026, 7:36 p.m.

0.0

CVE-2025-22295 - WordPress Tripetto plugin <= 8.0.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto tripetto allows Stored XSS.This issue affects WordPress form builder plugin for contact forms, surveys and q…

📅 Published: Jan. 9, 2025, 3:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345143
Page 6799 of 34,515
« previous page » next page
Filters