9.8

CVSS3.1

CVE-2024-40765 -

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

πŸ“… Published: Jan. 9, 2025, 7:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-53706 -

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.

πŸ“… Published: Jan. 9, 2025, 7:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0340 - code-projects Cinema Seat Reservation System deleteBooking.php sql injection

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/deleteBooking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The…

πŸ“… Published: Jan. 9, 2025, 7 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-0339 - code-projects Online Bike Rental HTTP GET Request vehical-details.php cross site scripting

A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown function of the file /vehical-details.php of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.

πŸ“… Published: Jan. 9, 2025, 7 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

7.5

CVSS3.1

CVE-2024-53705 -

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

πŸ“… Published: Jan. 9, 2025, 6:58 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-22445 - Misleading UI for undefined admin console settings in Calls causes security confusion

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

πŸ“… Published: Jan. 9, 2025, 6:55 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 5:25 p.m.

4.3

CVSS3.1

CVE-2025-20033 - DoS via custom post type for sysconsole plugin readers

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.

πŸ“… Published: Jan. 9, 2025, 6:55 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 5:26 p.m.

3.8

CVSS3.1

CVE-2025-22449 - Access control flaw for team admins allows unauthorized team additions

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

πŸ“… Published: Jan. 9, 2025, 6:54 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 5:44 p.m.

8.2

CVSS3.1

CVE-2024-53704 -

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

πŸ“… Published: Jan. 9, 2025, 6:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

9.8

CVSS3.1

CVE-2024-40762 -

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

πŸ“… Published: Jan. 9, 2025, 6:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345363
Page 6833 of 34,537
Β« previous page Β» next page
Filters