3.4

CVSS3.1

CVE-2024-54010 - Unauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 seriโ€ฆ

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuratโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 8:42 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-22145 - Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at โ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12431 - Missing Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

๐Ÿ“… Published: Jan. 8, 2025, 8:30 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-0194 - Insertion of Sensitive Information into Externally-Accessible File or Directory in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.

๐Ÿ“… Published: Jan. 8, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: July 11, 2025, 8:34 p.m.

6.9

CVSS4.0

CVE-2024-13189 - ZeroWdd myblog MyBlogMvcConfig.java permission

A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 8 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 8:12 p.m.

6.4

CVSS4.0

CVE-2025-22143 - WeGIA Cross-Site Scripting (XSS) Reflected endpoint 'listar_permissoes.php' parameter 'msg_e'

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_permissoes.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_e parameter. This vulnerability is fixedโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 7:42 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2025, 6:57 p.m.

4.8

CVSS4.0

CVE-2024-13188 - MicroWorld eScan Antivirus Installation var default permission

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the file /opt/MicroWorld/var/ of the component Installation Handler. The manipulation leads to incorrect default permissions. The attack neโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 7 p.m. ๐Ÿ”„ Last Modified: Oct. 9, 2025, 8:50 p.m.

8.3

CVSS3.1

CVE-2025-0291 -

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: Jan. 8, 2025, 6:42 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2025, 3:16 p.m.

9.4

CVSS4.0

CVE-2025-22141 - WeGIA SQL Injection (Blind Time-Based) endpoint 'verificar_recursos_cargo.php' parameter 'cargo'

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrityโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: April 9, 2025, 6:28 p.m.

6.4

CVSS4.0

CVE-2025-22139 - WeGIA Cross-Site Scripting (XSS) Reflected endpoint `configuracao_geral.php` parameter `msg`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixeโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 6:26 p.m. ๐Ÿ”„ Last Modified: April 9, 2025, 6:28 p.m.
Total resulsts: 345342
Page 6838 of 34,535
ยซ previous page ยป next page
Filters