4.3

CVSS3.1

CVE-2024-55923 - Cross-Site Request Forgery in Indexed Search Module in TYPO3

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstrea…

πŸ“… Published: Jan. 14, 2025, 7:20 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:35 p.m.

8

CVSS3.1

CVE-2024-55924 - Cross-Site Request Forgery in Scheduler Module in TYPO3

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstrea…

πŸ“… Published: Jan. 14, 2025, 7:16 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:35 p.m.

7.8

CVSS3.1

CVE-2025-21136 - Substance3D - Designer | Out-of-bounds Write (CWE-787)

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 7:16 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

7.8

CVSS3.1

CVE-2025-21138 - Substance3D - Designer | Out-of-bounds Write (CWE-787)

Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 7:16 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

7.8

CVSS3.1

CVE-2025-21139 - Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 7:16 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

7.8

CVSS3.1

CVE-2025-21137 - Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)

Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 7:16 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

4.3

CVSS3.1

CVE-2024-55945 - Cross-Site Request Forgery in DB Check Module in TYPO3

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Additionally, state-changing actions in downstrea…

πŸ“… Published: Jan. 14, 2025, 7:14 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 7:35 p.m.

3.1

CVSS3.1

CVE-2024-55891 - Information Disclosure via Exception Handling/Logger in TYPO3

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the prob…

πŸ“… Published: Jan. 14, 2025, 7:11 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:52 p.m.

7.8

CVSS3.1

CVE-2025-21135 - Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)

Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Jan. 14, 2025, 7:09 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 1:38 p.m.

7.5

CVSS3.1

CVE-2024-48858 - Vulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development Platform

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

πŸ“… Published: Jan. 14, 2025, 7:09 p.m. πŸ”„ Last Modified: Dec. 1, 2025, 6:06 p.m.
Total resulsts: 349182
Page 7117 of 34,919
Β« previous page Β» next page
Filters