5.8

CVSS3.1

CVE-2024-6437 - On affected platforms running Arista EOS with one of the following features configured to redirect …

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action a…

📅 Published: Jan. 10, 2025, 8:06 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-12847 - NETGEAR DGN setup.cgi OS Command Injection

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in…

📅 Published: Jan. 10, 2025, 7:36 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

6.1

CVSS3.1

CVE-2025-23079 - XSSes in Extension:ArticleFeedbackv5

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - ArticleFeedbackv5 extension: from 1.42.X before 1.42.2.

📅 Published: Jan. 10, 2025, 7:03 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-23078 - XSS in BreadCrumbs2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X befor…

📅 Published: Jan. 10, 2025, 5:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-6880 - CSRF in MegaBIP

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt fu…

📅 Published: Jan. 10, 2025, 5:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-6662 - CSRF in MegaBIP

Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms. A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If …

📅 Published: Jan. 10, 2025, 5:50 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS4.0

CVE-2025-22600 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `configuracao_doacao.php` parameter `avul…

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the avulso parameter. This vulnerability is fi…

📅 Published: Jan. 10, 2025, 3:30 p.m. 🔄 Last Modified: April 9, 2025, 6:26 p.m.

6.4

CVSS4.0

CVE-2025-22599 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.

8.3

CVSS3.1

CVE-2025-22598 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'cadastrarSocio.php' parameter 'nome'

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scripts a…

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:34 a.m.

8.3

CVSS3.1

CVE-2025-22597 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'CobrancaController.php' parameter 'local_re…

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scrip…

📅 Published: Jan. 10, 2025, 3:28 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:33 a.m.
Total resulsts: 349182
Page 7189 of 34,919
« previous page » next page
Filters