6.1

CVSS3.1

CVE-2024-50656 -

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 6:15 p.m.

9.8

CVSS3.1

CVE-2025-22978 -

eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-56902 -

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-22918 -

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2023-52164 -

access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-57175 -

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 5:57 p.m.

5.8

CVSS3.1

CVE-2025-25181 -

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2024-44449 -

Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-57452 -

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 7:39 p.m.

4.2

CVSS3.1

CVE-2024-54840 -

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 3:06 p.m.
Total resulsts: 349182
Page 6877 of 34,919
ยซ previous page ยป next page
Filters