8.8

CVSS3.1

CVE-2024-53355 -

Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/updatealias route; (4) delete users via the /api/us…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 3:37 p.m.

5.5

CVSS3.1

CVE-2025-21673 - smb: client: fix double free of TCP_Server_Info::hostname

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realizes it should exit the loop, so @server-…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

9.8

CVSS3.1

CVE-2024-53320 -

Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveCapture, and LoadProject functions.

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-57432 -

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentic…

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: Sept. 2, 2025, 9:26 p.m.

6.5

CVSS3.1

CVE-2024-57435 -

In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authentication, which triggers a denial-of-service attack and service restart failure.

πŸ“… Published: Jan. 31, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 3:27 p.m.

8

CVSS3.1

CVE-2024-23963 - Alpine Halo9 Stack-based Buffer Overflow

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists w…

πŸ“… Published: Jan. 30, 2025, 11:57 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 6:13 p.m.

5.3

CVSS3.1

CVE-2024-23962 - Alpine Halo9 Missing Authentication

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue resu…

πŸ“… Published: Jan. 30, 2025, 11:53 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 6:13 p.m.

2.6

CVSS3.1

CVE-2023-6195 - Server-Side Request Forgery (SSRF) in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.5 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. GitLab was vulnerable to Server Side Request Forgery when an attacker uses a malicious URL in the markdown image v…

πŸ“… Published: Jan. 30, 2025, 11:45 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:55 p.m.

6.4

CVSS3.1

CVE-2024-1211 - Cross-Site Request Forgery (CSRF) in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 in which cross-site request forgery may have been possible on GitLab instances configured to use JWT as an OmniAuth …

πŸ“… Published: Jan. 30, 2025, 11:45 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:57 p.m.

8.8

CVSS3.1

CVE-2024-23971 - ChargePoint Home Flex OCPP bswitch Command Injection

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from t…

πŸ“… Published: Jan. 30, 2025, 11:42 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:43 p.m.
Total resulsts: 349182
Page 6900 of 34,919
Β« previous page Β» next page
Filters