9.8

CVSS3.1

CVE-2025-22916 -

RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:42 p.m.

4.6

CVSS3.1

CVE-2024-40513 -

An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Sept. 30, 2025, 9:20 p.m.

8.7

CVSS3.1

CVE-2024-54660 -

A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the databas…

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-57161 -

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Feb. 24, 2025, 7:38 p.m.

6.5

CVSS3.1

CVE-2024-57679 -

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 7:31 p.m.

4.6

CVSS3.1

CVE-2024-40514 -

Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via the User profile name and image upload functions.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Sept. 30, 2025, 9:17 p.m.

0

CVSS3.1

CVE-2024-50633 -

A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain informat…

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 6:48 p.m.

5.5

CVSS3.1

CVE-2024-57784 -

An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-57579 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 9:15 p.m.

8.8

CVSS3.1

CVE-2024-57775 -

JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Jan. 31, 2025, 9:15 p.m.
Total resulsts: 349182
Page 7094 of 34,919
Β« previous page Β» next page
Filters