4.4

CVSS3.1

CVE-2025-25063 -

An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 6:54 p.m.

5

CVSS3.1

CVE-2024-57966 -

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:31 a.m.

9.8

CVSS3.1

CVE-2024-57098 -

Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 6:23 p.m.

9.8

CVSS3.1

CVE-2024-57450 -

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 7:40 p.m.

4.8

CVSS3.1

CVE-2024-57498 -

Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 6:09 p.m.

7.5

CVSS3.1

CVE-2024-56921 -

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 2:58 p.m.

7.5

CVSS3.1

CVE-2024-57669 -

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 4:15 p.m.

9.9

CVSS3.1

CVE-2024-57968 -

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 4:38 p.m.

6.4

CVSS3.1

CVE-2024-57522 -

SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 8:08 p.m.

4.8

CVSS3.1

CVE-2024-53942 -

An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via …

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 4:15 p.m.
Total resulsts: 343168
Page 6277 of 34,317
Β« previous page Β» next page
Filters