9.8

CVSS3.1

CVE-2024-57687 -

An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 7:16 p.m.

5.9

CVSS3.1

CVE-2024-54846 -

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 2, 2025, 5:17 p.m.

4

CVSS3.1

CVE-2024-57822 - raptor: heap-based buffer over-read vulnerability

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 6:15 p.m.

9.8

CVSS3.1

CVE-2025-22949 -

Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: April 9, 2025, 6:36 p.m.

6.5

CVSS3.1

CVE-2024-54994 -

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-29971 -

Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 29, 2025, 3:37 p.m.

6.1

CVSS3.1

CVE-2025-23110 -

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV file containing a list of alert configurations. An attacker can send the victim a CSV file containing the XSS payload in the email-subโ€ฆ

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 25, 2025, 4:46 p.m.

4

CVSS3.1

CVE-2025-23022 - freetype: signed integer overflow in cf2_doFlex

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

7.2

CVSS3.1

CVE-2024-46210 -

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: June 13, 2025, 6:24 p.m.

9.8

CVSS3.1

CVE-2024-57223 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 2:05 p.m.
Total resulsts: 349182
Page 7192 of 34,919
ยซ previous page ยป next page
Filters