6.1

CVSS3.1

CVE-2024-44449 -

Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 6:15 p.m.

7.3

CVSS3.1

CVE-2024-57238 -

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 8:15 p.m.

8.8

CVSS3.1

CVE-2024-56901 -

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF att…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: March 4, 2025, 10:15 p.m.

6.5

CVSS3.1

CVE-2024-55456 -

lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 5:07 p.m.

6.1

CVSS3.1

CVE-2024-57004 -

Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 4:03 p.m.

6.3

CVSS3.1

CVE-2024-57237 -

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the bro…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: March 3, 2025, 6:15 p.m.

9.8

CVSS3.1

CVE-2024-57099 -

ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 7:57 p.m.

7.5

CVSS3.1

CVE-2024-57451 -

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 7:31 p.m.

4.8

CVSS3.1

CVE-2024-57097 -

ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 7:15 p.m.

8.8

CVSS3.1

CVE-2023-52163 -

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 343944
Page 6354 of 34,395
Β« previous page Β» next page
Filters