7.8

CVSS3.1

CVE-2024-53706 -

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.

πŸ“… Published: Jan. 9, 2025, 7:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-0340 - code-projects Cinema Seat Reservation System deleteBooking.php sql injection

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/deleteBooking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The…

πŸ“… Published: Jan. 9, 2025, 7 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

5.3

CVSS4.0

CVE-2025-0339 - code-projects Online Bike Rental HTTP GET Request vehical-details.php cross site scripting

A vulnerability classified as problematic has been found in code-projects Online Bike Rental 1.0. Affected is an unknown function of the file /vehical-details.php of the component HTTP GET Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.

πŸ“… Published: Jan. 9, 2025, 7 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

7.5

CVSS3.1

CVE-2024-53705 -

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.

πŸ“… Published: Jan. 9, 2025, 6:58 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-22445 - Misleading UI for undefined admin console settings in Calls causes security confusion

Mattermost versions 10.x <= 10.2 fail to accurately reflect missing settings, which allows confusion for admins regarding a Calls security-sensitive configuration via incorrect UI reporting.

πŸ“… Published: Jan. 9, 2025, 6:55 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 5:25 p.m.

4.3

CVSS3.1

CVE-2025-20033 - DoS via custom post type for sysconsole plugin readers

Mattermost versions 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post types, which allows attackers to deny service to users with the sysconsole_read_plugins permission via creating a post with the custom_pl_notification type and specific props.

πŸ“… Published: Jan. 9, 2025, 6:55 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 5:26 p.m.

3.8

CVSS3.1

CVE-2025-22449 - Access control flaw for team admins allows unauthorized team additions

Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.

πŸ“… Published: Jan. 9, 2025, 6:54 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 5:44 p.m.

8.2

CVSS3.1

CVE-2024-53704 -

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

πŸ“… Published: Jan. 9, 2025, 6:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

9.8

CVSS3.1

CVE-2024-40762 -

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

πŸ“… Published: Jan. 9, 2025, 6:43 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2024-13041 - Incorrect User Management in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As …

πŸ“… Published: Jan. 9, 2025, 6:33 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:12 p.m.
Total resulsts: 349182
Page 7215 of 34,919
Β« previous page Β» next page
Filters