5.3

CVSS4.0

CVE-2025-0973 - CmsEasy index.php backAll_action path traversal

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument select[] leads to pโ€ฆ

๐Ÿ“… Published: Feb. 3, 2025, 12:31 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-0972 - Zenvia Movidesk New Ticket cross site scripting

A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. The manipulation of the argument subject leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 10, 2025, 2:57 p.m.

4.2

CVSS3.1

CVE-2024-57967 -

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: July 15, 2025, 8:04 a.m.

7.5

CVSS3.1

CVE-2024-34896 -

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2024-34897 -

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 18, 2025, 9:15 p.m.

6.5

CVSS3.1

CVE-2024-36437 -

The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity compโ€ฆ

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 5, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2025-22978 -

eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 2:15 p.m.

7.5

CVSS3.1

CVE-2024-56902 -

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 4, 2025, 10:15 p.m.

7.5

CVSS3.1

CVE-2025-22918 -

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 18, 2025, 7:15 p.m.

8.1

CVSS3.1

CVE-2024-56903 -

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

๐Ÿ“… Published: Feb. 3, 2025, midnight ๐Ÿ”„ Last Modified: March 4, 2025, 10:15 p.m.
Total resulsts: 343947
Page 6353 of 34,395
ยซ previous page ยป next page
Filters