6.4

CVSS3.1

CVE-2024-57522 -

SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 8:08 p.m.

8.1

CVSS3.1

CVE-2025-25066 -

nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:29 p.m.

8.8

CVSS3.1

CVE-2025-25064 -

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied parameter. Authenticated attackers can exploit this vulnerability by manipulating a specific parameter in th…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

5

CVSS3.1

CVE-2024-57966 -

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-25065 -

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: June 11, 2025, 9:18 p.m.

4.4

CVSS3.1

CVE-2025-25062 -

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administr…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 6:46 p.m.

6.3

CVSS3.1

CVE-2024-57237 -

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the bro…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-53943 -

An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute JavaScript within the context of the current user by injecting JavaScript into the SSID fi…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-56901 -

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF att…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.9

CVSS3.1

CVE-2024-57968 -

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 4:38 p.m.
Total resulsts: 349182
Page 6878 of 34,919
Β« previous page Β» next page
Filters