8.4

CVSS4.0

CVE-2025-24803 - Stored Cross-Site Scripting (XSS) in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), …

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: July 7, 2025, 1:41 p.m.

4.8

CVSS4.0

CVE-2025-24804 - Partial Denial of Service (DoS) in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), …

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: May 23, 2025, 5:18 p.m.

8.5

CVSS4.0

CVE-2025-24805 - Local Privilege Escalation in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepte…

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: May 23, 2025, 5:01 p.m.

7.3

CVSS3.1

CVE-2025-24372 - XSS vector in user uploaded images in group/org and user profiles in ckan

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload a file containing code that when executed could send arbitrary requests to the server. If that file was opened by an administrator, it could l…

📅 Published: Feb. 5, 2025, 6:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2024-56135 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:02 p.m. 🔄 Last Modified: July 31, 2025, 1:47 p.m.

8.4

CVSS3.1

CVE-2024-56134 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:02 p.m. 🔄 Last Modified: July 31, 2025, 2:02 p.m.

8.4

CVSS3.1

CVE-2024-56133 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:01 p.m. 🔄 Last Modified: July 31, 2025, 2:06 p.m.

8.4

CVSS3.1

CVE-2024-56132 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:01 p.m. 🔄 Last Modified: July 31, 2025, 2:11 p.m.

8.4

CVSS3.1

CVE-2024-56131 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6 p.m. 🔄 Last Modified: July 31, 2025, 2:13 p.m.

5.3

CVSS4.0

CVE-2025-23419 - TLS Session Resumption Vulnerability

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.…

📅 Published: Feb. 5, 2025, 5:31 p.m. 🔄 Last Modified: Jan. 27, 2026, 1:30 p.m.
Total resulsts: 349182
Page 6837 of 34,919
« previous page » next page
Filters