4.3

CVSS3.1

CVE-2024-54176 - IBM UrbanCode Deploy missing authentication

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorizaโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 4:15 p.m. ๐Ÿ”„ Last Modified: Aug. 15, 2025, 12:33 p.m.

6.9

CVSS4.0

CVE-2025-1117 - CoinRemitter sql injection

A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an unknown part. The manipulation of the argument coin leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be uโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 12:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-13850 - Simple add pages or posts <= 2.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbiโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 12:21 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:57 p.m.

6.9

CVSS4.0

CVE-2025-1116 - Dreamvention Live AJAX Search Free live_search.searchresults search sql injection

A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart. Affected by this issue is the function searchresults/search of the file /?route=extension/live_search/module/live_search.searchresults. The manipulation of the argument kโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1115 - RT-Thread lwp_syscall.c sys_timer_settime information disclosure

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_device_control/sys_device_find/sys_device_init/sys_device_open/sys_device_read/sys_device_register/sys_device_write/sys_event_delete/sys_event_recv/sys_eโ€ฆ

๐Ÿ“… Published: Feb. 8, 2025, 10 a.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 7:53 p.m.

7.8

CVSS3.1

CVE-2025-25187 - Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Contenโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 10:38 p.m. ๐Ÿ”„ Last Modified: April 11, 2025, 6:56 p.m.

5.1

CVSS4.0

CVE-2025-1114 - newbee-mall Add Category Page save cross site scripting

A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack remotelyโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: June 20, 2025, 5 p.m.

7.8

CVSS3.1

CVE-2025-24028 - Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text โ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 10:23 p.m. ๐Ÿ”„ Last Modified: April 18, 2025, 1:57 a.m.

3.3

CVSS3.1

CVE-2024-55630 - DOM Clobbering leads to temporary DOS in the note viewer in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), thatโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 10:23 p.m. ๐Ÿ”„ Last Modified: April 18, 2025, 2:10 a.m.

5.3

CVSS4.0

CVE-2025-1113 - taisan tarzan-cms Add Theme admin#themes upload deserialization

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: Feb. 7, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2025, 8:29 p.m.
Total resulsts: 349182
Page 6813 of 34,919
ยซ previous page ยป next page
Filters