6.5

CVSS3.1

CVE-2024-56953 -

An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-0736 - Org.infinispan-infinispan-parent: exposure of sensitive information in application logs

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious…

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-48418 -

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:53 p.m.

9

CVSS3.1

CVE-2024-55228 -

A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: Feb. 19, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2024-57547 -

Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 11, 2025, 7:09 p.m.

5.2

CVSS3.1

CVE-2024-48417 -

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 5:54 p.m.

9.8

CVSS3.1

CVE-2024-57590 -

TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:01 p.m.

6.5

CVSS3.1

CVE-2024-56967 -

An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-57276 -

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, en…

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-57595 -

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

πŸ“… Published: Jan. 27, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6953 of 34,919
Β« previous page Β» next page
Filters