4.8

CVSS4.0

CVE-2025-1115 - RT-Thread lwp_syscall.c sys_timer_settime information disclosure

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_device_control/sys_device_find/sys_device_init/sys_device_open/sys_device_read/sys_device_register/sys_device_write/sys_event_delete/sys_event_recv/sys_e…

📅 Published: Feb. 8, 2025, 10 a.m. 🔄 Last Modified: Nov. 4, 2025, 7:53 p.m.

7.8

CVSS3.1

CVE-2025-25187 - Cross-site Scripting in Goto Anything allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Conten…

📅 Published: Feb. 7, 2025, 10:38 p.m. 🔄 Last Modified: April 11, 2025, 6:56 p.m.

5.1

CVSS4.0

CVE-2025-1114 - newbee-mall Add Category Page save cross site scripting

A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack remotely…

📅 Published: Feb. 7, 2025, 10:31 p.m. 🔄 Last Modified: June 20, 2025, 5 p.m.

7.8

CVSS3.1

CVE-2025-24028 - Cross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text …

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 1:57 a.m.

3.3

CVSS3.1

CVE-2024-55630 - DOM Clobbering leads to temporary DOS in the note viewer in Joplin

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g. `querySelector`), that…

📅 Published: Feb. 7, 2025, 10:23 p.m. 🔄 Last Modified: April 18, 2025, 2:10 a.m.

5.3

CVSS4.0

CVE-2025-1113 - taisan tarzan-cms Add Theme admin#themes upload deserialization

A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the function upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been discl…

📅 Published: Feb. 7, 2025, 9:31 p.m. 🔄 Last Modified: Aug. 21, 2025, 8:29 p.m.

7.5

CVSS3.1

CVE-2025-24366 - Insufficient sanitization of user provided rsync command in SFTPGo

SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default commands some optional commands can be activated, one of them being `rsync`. It is disabled in the default configuration and it is limited to the l…

📅 Published: Feb. 7, 2025, 9:16 p.m. 🔄 Last Modified: Feb. 7, 2025, 10:49 p.m.

6.9

CVSS4.0

CVE-2025-24980 - Pimcore Admin Classic Bundle allows user enumeration

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target via "Forgot password" function. No generic error message has been implemented. This issue has been addressed in version 1.…

📅 Published: Feb. 7, 2025, 7:56 p.m. 🔄 Last Modified: Jan. 16, 2026, 6:16 p.m.

5.3

CVSS4.0

CVE-2021-41528 - Improper authorization related to Import / Export interfaces on RISC Platform

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

📅 Published: Feb. 7, 2025, 7:54 p.m. 🔄 Last Modified: Feb. 7, 2025, 9:18 p.m.

2.3

CVSS4.0

CVE-2021-41527 - 2FA bypass on the RISC Platform

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

📅 Published: Feb. 7, 2025, 7:44 p.m. 🔄 Last Modified: March 13, 2025, 2:15 p.m.
Total resulsts: 343757
Page 6271 of 34,376
« previous page » next page
Filters