4.3

CVSS3.0

CVE-2025-24982 -

Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.

πŸ“… Published: Feb. 4, 2025, 4:18 a.m. πŸ”„ Last Modified: Feb. 4, 2025, 4:39 p.m.

0.0

CVE-2025-25049 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Feb. 4, 2025, 4 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

0.0

CVE-2025-24492 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Feb. 4, 2025, 4 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

0.0

CVE-2025-24321 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Feb. 4, 2025, 4 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

3.7

CVSS3.1

CVE-2025-22475 -

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information tampering.

πŸ“… Published: Feb. 4, 2025, 2:19 a.m. πŸ”„ Last Modified: Feb. 7, 2025, 8:42 p.m.

9.8

CVSS3.1

CVE-2024-48445 -

An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.

πŸ“… Published: Feb. 4, 2025, midnight πŸ”„ Last Modified: Feb. 6, 2025, 3:15 p.m.

8.5

CVSS4.0

CVE-2025-1003 - HP Anyware Agent for Linux – Potential Authentication Bypass

A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software update to mitigate this potential vulnerability.

πŸ“… Published: Feb. 3, 2025, 11:56 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 3:44 p.m.

2.6

CVSS3.1

CVE-2025-0148 - Zoom Jenkins Marketplace plugin - Missing Password Field Masking

Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.

πŸ“… Published: Feb. 3, 2025, 10:35 p.m. πŸ”„ Last Modified: Feb. 4, 2025, 3:44 p.m.

9.4

CVSS4.0

CVE-2025-24901 - SQL Injection endpoint 'deletar_permissao.php' parameter 'c', 'a', 'r' in WeGIA

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive informati…

πŸ“… Published: Feb. 3, 2025, 9:43 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 7:01 p.m.

9.4

CVSS4.0

CVE-2025-24902 - SQL Injection endpoint 'salvar_cargo.php' parameter 'id_cargo' in WeGIA

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. T…

πŸ“… Published: Feb. 3, 2025, 9:43 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 9:15 p.m.
Total resulsts: 343996
Page 6343 of 34,400
Β« previous page Β» next page
Filters