8.7

CVSS4.0

CVE-2025-1025 -

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

πŸ“… Published: Feb. 5, 2025, 5 a.m. πŸ”„ Last Modified: July 12, 2025, 3:26 p.m.

8.8

CVSS4.0

CVE-2025-1022 -

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../../../etc/passwd). This is due to missing validations of the u…

πŸ“… Published: Feb. 5, 2025, 5 a.m. πŸ”„ Last Modified: July 21, 2025, 3:17 p.m.

7.7

CVSS4.0

CVE-2025-1026 -

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files. **Note:** This is a bypass of the fix for [CVE-2024-…

πŸ“… Published: Feb. 5, 2025, 5 a.m. πŸ”„ Last Modified: June 17, 2025, 12:08 p.m.

8.1

CVSS3.1

CVE-2025-1028 - Contact Manager <= 8.6.4 - Unauthenticated Arbitrary Double File Extension Upload

The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload feature in all versions up to, and including, 8.6.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's …

πŸ“… Published: Feb. 5, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

9

CVSS3.0

CVE-2025-23114 -

A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.

πŸ“… Published: Feb. 5, 2025, 1:45 a.m. πŸ”„ Last Modified: March 13, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2024-57080 -

A prototype pollution in the lib.install function of vxe-table v4.8.10 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

πŸ“… Published: Feb. 5, 2025, midnight πŸ”„ Last Modified: Feb. 6, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2023-52924 - netfilter: nf_tables: don't skip expired elements during walk

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and preparation phase if the following conditions are met: 1. set is a verdict map ("1.2.3.4 : jump foo") 2. timeouts are e…

πŸ“… Published: Feb. 5, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 8:04 p.m.

4.3

CVSS3.1

CVE-2025-1057 - Keylime: keylime registrar dos due to incompatible database entry handling

A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas th…

πŸ“… Published: Feb. 5, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 8 p.m.

7.5

CVSS3.1

CVE-2024-57085 -

A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

πŸ“… Published: Feb. 5, 2025, midnight πŸ”„ Last Modified: March 13, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2024-57063 -

A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

πŸ“… Published: Feb. 5, 2025, midnight πŸ”„ Last Modified: Feb. 6, 2025, 4:15 p.m.
Total resulsts: 343947
Page 6320 of 34,395
Β« previous page Β» next page
Filters