9.3

CVSS3.1

CVE-2025-24981 - Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the `javascript:` protocol scheme in the URL. Th…

📅 Published: Feb. 6, 2025, 5:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-22867 - Arbitrary code execution during build on darwin in cmd/go

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special values in a "#cgo LDFLAGS" directive. This issue only affected go1.24rc2.

📅 Published: Feb. 6, 2025, 5:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1078 - AppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcc…

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper of the component XPC Service. The manipulation leads to impro…

📅 Published: Feb. 6, 2025, 5 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-22866 - Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private ke…

📅 Published: Feb. 6, 2025, 4:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2024-39272 -

A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability.

📅 Published: Feb. 6, 2025, 4:47 p.m. 🔄 Last Modified: Sept. 5, 2025, 5:32 p.m.

7.7

CVSS3.1

CVE-2024-43779 -

An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been previously disabled, possibly leaking sensitive credentials. An attacker can send a series of HTTP reque…

📅 Published: Feb. 6, 2025, 4:47 p.m. 🔄 Last Modified: Sept. 5, 2025, 5:44 p.m.

5.3

CVSS3.1

CVE-2024-13614 -

Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office Security, Kaspersky for Windows (Standard, Plus, Premium), Kaspersky Free, Kaspersky Anti-Virus, Kaspersky…

📅 Published: Feb. 6, 2025, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-0994 -

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (II…

📅 Published: Feb. 6, 2025, 4:01 p.m. 🔄 Last Modified: Oct. 30, 2025, 3:54 p.m.

8.5

CVSS3.1

CVE-2022-31764 - Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of t…

📅 Published: Feb. 6, 2025, 2:23 p.m. 🔄 Last Modified: July 16, 2025, 1 a.m.

9.4

CVSS4.0

CVE-2023-5878 - OneWireless command injection possible when updating firmware

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leadin…

📅 Published: Feb. 6, 2025, 2:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6828 of 34,919
« previous page » next page
Filters