5.3

CVSS4.0

CVE-2025-1158 - ESAFENET CDG addPolicyToSafetyGroup.jsp sql injection

A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injection. It is possible to launch the attack remotely. The explโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1157 - Allims lab.online model_recuperar_senha.php sql injection

A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql injection. The attack may be initiated remotely. The exploit hโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 9 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2025-1002 - MicroDicom DICOM Viewer Improper Certificate Validation

MicroDicom DICOM Viewerย version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the servโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: March 3, 2025, 4:52 p.m.

6.9

CVSS4.0

CVE-2025-1156 - Pix Software Vivaz servlet sql injection

A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login. The manipulation of the argument usuario leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to thโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 8:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1155 - Webkul QloApps Your Location Search stores cross site scripting

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove thโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 8 p.m. ๐Ÿ”„ Last Modified: June 20, 2025, 5:02 p.m.

5.3

CVSS4.0

CVE-2025-1154 - xxyopen Novel books sql injection

A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue is some unknown functionality of the file /api/front/search/books. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit haโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 7:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2025-24016 - Remote code execution in Wazuh server

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 7:08 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2025-24200 - Authorization Flaw Allowing Disabling of USB Restricted Mode on Locked Devices

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report thaโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 7:04 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 3:45 a.m.

2.3

CVSS4.0

CVE-2025-1153 - GNU Binutils format.c bfd_set_format memory corruption

A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 7 p.m. ๐Ÿ”„ Last Modified: April 4, 2025, 11:15 p.m.

7.2

CVSS3.0

CVE-2024-13059 - Path Traversal in mintplex-labs/anything-llm

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result in remote code execution. The issue arises when thโ€ฆ

๐Ÿ“… Published: Feb. 10, 2025, 6:53 p.m. ๐Ÿ”„ Last Modified: July 9, 2025, 3:11 p.m.
Total resulsts: 349182
Page 6806 of 34,919
ยซ previous page ยป next page
Filters