9.7

CVSS3.1

CVE-2025-24891 - Dumb Drop has an arbitrary file overwrite and path traversal for root shell

Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as root by default, there is no limit to what can be overwritten. With this, it's possible to inject m…

πŸ“… Published: Jan. 31, 2025, 11:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0934 - code-projects Job Recruitment _call_job_search_ajax.php sql injection

A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. This affects an unknown part of the file /parse/_call_job_search_ajax.php. The manipulation of the argument n leads to sql injection. It is possible to initiate the attack remotely. The exploit ha…

πŸ“… Published: Jan. 31, 2025, 7:31 p.m. πŸ”„ Last Modified: Feb. 18, 2025, 6:49 p.m.

6.3

CVSS4.0

CVE-2025-0938 - URL parser allowed square brackets in domain names

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in dif…

πŸ“… Published: Jan. 31, 2025, 5:51 p.m. πŸ”„ Last Modified: April 22, 2026, 12:15 p.m.

6.1

CVSS3.1

CVE-2024-49349 - IBM Financial Transaction Manager cross-site scripting

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t…

πŸ“… Published: Jan. 31, 2025, 4:14 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 5:34 p.m.

6.4

CVSS3.1

CVE-2024-49339 - IBM Financial Transaction Manager cross-site scripting

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t…

πŸ“… Published: Jan. 31, 2025, 4:13 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 5:40 p.m.

5.4

CVSS3.1

CVE-2024-47116 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr…

πŸ“… Published: Jan. 31, 2025, 4:01 p.m. πŸ”„ Last Modified: March 5, 2025, 6:17 p.m.

4.3

CVSS3.1

CVE-2024-45089 - IBM Sterling B2B Integrator information disclosure

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.

πŸ“… Published: Jan. 31, 2025, 3:58 p.m. πŸ”„ Last Modified: March 5, 2025, 6:17 p.m.

9.3

CVSS4.0

CVE-2025-23215 - PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext

PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing keys are included in jar published to Maven Central. The private key itself is not known to have been compromised itself, but given its passphrase is, it must also be considered pote…

πŸ“… Published: Jan. 31, 2025, 3:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-49807 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading …

πŸ“… Published: Jan. 31, 2025, 3:25 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

4.8

CVSS3.1

CVE-2024-40696 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden…

πŸ“… Published: Jan. 31, 2025, 3:24 p.m. πŸ”„ Last Modified: March 5, 2025, 6:17 p.m.
Total resulsts: 349182
Page 6885 of 34,919
Β« previous page Β» next page
Filters