4.8

CVSS3.1

CVE-2024-38317 - IBM Aspera Shares Cross-Site Scripting

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Feb. 5, 2025, 10:43 p.m. 🔄 Last Modified: March 7, 2025, 7:37 p.m.

4.3

CVSS3.1

CVE-2024-38316 - IBM Aspera Shares Denial of Service

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

📅 Published: Feb. 5, 2025, 10:30 p.m. 🔄 Last Modified: March 6, 2025, 8:57 p.m.

0.0

CVE-2024-13837 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: Feb. 5, 2025, 8:23 p.m. 🔄 Last Modified: Feb. 17, 2025, 7:15 p.m.

8.4

CVSS4.0

CVE-2025-24803 - Stored Cross-Site Scripting (XSS) in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), …

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: July 7, 2025, 1:41 p.m.

4.8

CVSS4.0

CVE-2025-24804 - Partial Denial of Service (DoS) in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), …

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: May 23, 2025, 5:18 p.m.

8.5

CVSS4.0

CVE-2025-24805 - Local Privilege Escalation in MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepte…

📅 Published: Feb. 5, 2025, 6:41 p.m. 🔄 Last Modified: May 23, 2025, 5:01 p.m.

7.3

CVSS3.1

CVE-2025-24372 - XSS vector in user uploaded images in group/org and user profiles in ckan

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload a file containing code that when executed could send arbitrary requests to the server. If that file was opened by an administrator, it could l…

📅 Published: Feb. 5, 2025, 6:12 p.m. 🔄 Last Modified: July 13, 2025, 11:07 a.m.

8.4

CVSS3.1

CVE-2024-56135 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:02 p.m. 🔄 Last Modified: July 31, 2025, 1:47 p.m.

8.4

CVSS3.1

CVE-2024-56134 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:02 p.m. 🔄 Last Modified: July 31, 2025, 2:02 p.m.

8.4

CVSS3.1

CVE-2024-56133 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Co…

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive)    From 7.2.49.0 to 7.2.54.12 (inclusive)    …

📅 Published: Feb. 5, 2025, 6:01 p.m. 🔄 Last Modified: July 31, 2025, 2:06 p.m.
Total resulsts: 343924
Page 6311 of 34,393
« previous page » next page
Filters