6.5

CVSS3.1

CVE-2024-23970 - ChargePoint Home Flex Improper Certificate Validation

This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue re…

πŸ“… Published: Jan. 30, 2025, 11:40 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:45 p.m.

8.8

CVSS3.1

CVE-2024-23969 - ChargePoint Home Flex wlanchnllst Out-Of-Bounds Write

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from the la…

πŸ“… Published: Jan. 30, 2025, 11:37 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:49 p.m.

8.8

CVSS3.1

CVE-2024-23968 - ChargePoint Home Flex SrvrToSmSetAutoChnlListMsg Stack-based Buffer Overflow

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue resu…

πŸ“… Published: Jan. 30, 2025, 11:31 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:50 p.m.

8.8

CVSS3.1

CVE-2024-23973 - Silicon Labs Gecko OS HTTP GET Request Handling Stack-based Buffer Overflow

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability.Β  The specific flaw exists within the handling of HTTP GET requests. The issue results from the lack of pr…

πŸ“… Published: Jan. 30, 2025, 11:28 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:42 p.m.

7.5

CVSS3.1

CVE-2024-24731 - Silicon Labs Gecko OS http_download Stack-based Buffer Overflow

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the http_download command. The issue results from t…

πŸ“… Published: Jan. 30, 2025, 11:25 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:09 p.m.

7.6

CVSS3.1

CVE-2025-24885 - pwn.college has a XSS on dojo pages

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.

πŸ“… Published: Jan. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.1

CVE-2025-24886 - pwn.college has Symlink LFI in Dojo repos

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check…

πŸ“… Published: Jan. 30, 2025, 10:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0882 - code-projects Chat System addnewmember.php sql injection

A vulnerability was found in code-projects Chat System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/addnewmember.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The e…

πŸ“… Published: Jan. 30, 2025, 9 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2025-0881 - Codezips Gym Management System saveroutine.php sql injection

A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. The manipulation of the argument rname leads to sql injection. It is possible to launch the attack remotely. The exploit…

πŸ“… Published: Jan. 30, 2025, 8:31 p.m. πŸ”„ Last Modified: April 23, 2025, 9:49 p.m.

5.3

CVSS4.0

CVE-2025-0880 - Codezips Gym Management System updateplan.php sql injection

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/updateplan.php. The manipulation of the argument planid leads to sql injection. The attack may be initiated remotely. The exploit has b…

πŸ“… Published: Jan. 30, 2025, 8:31 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 7:20 p.m.
Total resulsts: 349182
Page 6901 of 34,919
Β« previous page Β» next page
Filters