7.2

CVSS3.1

CVE-2024-10237 - SMC BMC Firmware Image Authentication Design Issue

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process

πŸ“… Published: Feb. 4, 2025, 7:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2025-20907 -

Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

πŸ“… Published: Feb. 4, 2025, 7:24 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 1:49 p.m.

5.5

CVSS3.1

CVE-2025-20906 -

Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.

πŸ“… Published: Feb. 4, 2025, 7:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-20905 -

Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

πŸ“… Published: Feb. 4, 2025, 7:24 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 1:49 p.m.

6.3

CVSS3.1

CVE-2025-20904 -

Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

πŸ“… Published: Feb. 4, 2025, 7:24 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 1:48 p.m.

7.5

CVSS3.1

CVE-2025-22205 - Extension - admiror-design-studio.com - Path traversal in the Admiror Gallery 4.x component for Joo…

Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.

πŸ“… Published: Feb. 4, 2025, 7:21 a.m. πŸ”„ Last Modified: June 4, 2025, 8:52 p.m.

4.3

CVSS3.1

CVE-2024-12046 - Medical Addon for Elementor <= 1.6.2 - Insecure Direct Object Reference to Authenticated (Contribut…

The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…

πŸ“… Published: Feb. 4, 2025, 7:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-13514 - B Slider- Gutenberg Slider Block for WP <= 1.1.23 - Authenticated (Contributor+) Private Post Discl…

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with…

πŸ“… Published: Feb. 4, 2025, 7:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-22204 - Extension - regularlabs.com - Remote code execution vulnerability in the Sourcerer extensions < 12.…

Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

πŸ“… Published: Feb. 4, 2025, 7:20 a.m. πŸ”„ Last Modified: June 4, 2025, 8:53 p.m.

5.1

CVSS3.1

CVE-2025-20902 -

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

πŸ“… Published: Feb. 4, 2025, 7:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6857 of 34,919
Β« previous page Β» next page
Filters