7.5

CVSS3.1

CVE-2024-57669 -

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-56921 -

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 2:58 p.m.

4.8

CVSS3.1

CVE-2024-57498 -

Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 6:09 p.m.

9.8

CVSS3.1

CVE-2024-57450 -

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 7:40 p.m.

9.8

CVSS3.1

CVE-2024-57098 -

Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:23 p.m.

8.8

CVSS3.1

CVE-2024-56898 -

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-25063 -

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 6:54 p.m.

5.3

CVSS3.1

CVE-2024-56946 -

Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the server from accepting new DNS-over-QUIC connections by triggering unhandled exceptions in listener threads.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 5:16 p.m.

8.8

CVSS3.1

CVE-2023-52163 -

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.5

CVSS3.1

CVE-2024-34896 -

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6879 of 34,919
Β« previous page Β» next page
Filters