5.3

CVSS3.1

CVE-2024-49354 - IBM Concert information disclosure

IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Calls.

πŸ“… Published: Jan. 18, 2025, 3:17 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 2:10 a.m.

6.5

CVSS3.1

CVE-2024-49824 - IBM Robotic Process Automation security bypass

IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validatio…

πŸ“… Published: Jan. 18, 2025, 3:11 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 5:56 p.m.

6.7

CVSS3.1

CVE-2024-51448 - IBM Robotic Process Automation privilege escalation

IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe …

πŸ“… Published: Jan. 18, 2025, 3:08 p.m. πŸ”„ Last Modified: March 25, 2025, 2:06 p.m.

5.1

CVSS4.0

CVE-2025-0560 - CampCodes School Management Software Photo Gallery Page photo-gallery cross site scripting

A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /photo-gallery of the component Photo Gallery Page. The manipulation of the argument Description leads to cross site scripting. It is possible to …

πŸ“… Published: Jan. 18, 2025, 3 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 2:02 a.m.

4.4

CVSS3.1

CVE-2024-49338 - IBM App Connect Enterprise information disclosure

IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.

πŸ“… Published: Jan. 18, 2025, 3 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 12:24 a.m.

5.1

CVSS4.0

CVE-2025-0559 - Campcodes School Management Software Create Id Card Page create-id-card cross site scripting

A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This issue affects some unknown processing of the file /create-id-card of the component Create Id Card Page. The manipulation of the argument ID Card Title leads to cross site scripting…

πŸ“… Published: Jan. 18, 2025, 2 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 2:02 a.m.

5.3

CVSS4.0

CVE-2025-0558 - TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection

A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation of the argument color leads to sql injection. The …

πŸ“… Published: Jan. 18, 2025, 1 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 6:40 p.m.

6.9

CVSS4.0

CVE-2025-0557 - Hyland Alfresco Community Edition URL s cross site scripting

A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the …

πŸ“… Published: Jan. 18, 2025, 9 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-13375 - Adifier System <= 3.1.7 - Unauthenticated Arbitrary Password Reset

The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the adifier_recover() function. T…

πŸ“… Published: Jan. 18, 2025, 8:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-13184 - The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login At…

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing S…

πŸ“… Published: Jan. 18, 2025, 8:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7052 of 34,919
Β« previous page Β» next page
Filters