4.5

CVSS3.1

CVE-2024-57523 -

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 8:06 p.m.

9.3

CVSS3.1

CVE-2024-57428 -

A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, …

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:13 a.m.

8.1

CVSS3.1

CVE-2024-54909 -

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 3:15 p.m.

8.6

CVSS3.1

CVE-2024-57609 -

An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2025, 10:15 p.m.

8.8

CVSS3.1

CVE-2025-23093 -

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an at…

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2024-25883 -

The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 11, 2025, 2:34 p.m.

5.4

CVSS3.1

CVE-2024-57429 -

A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:13 a.m.

5.7

CVSS3.1

CVE-2025-22936 -

An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 2:15 p.m.

5.5

CVSS3.1

CVE-2024-57673 -

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 9:57 p.m.

4.8

CVSS3.1

CVE-2022-40490 -

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 7:40 p.m.
Total resulsts: 343921
Page 6307 of 34,393
Β« previous page Β» next page
Filters