6.6

CVSS3.1

CVE-2024-36557 -

The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b. If a malicious user changes the IMEI to the IMEI of a unit they registered in the mobile app, it โ€ฆ

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-54909 -

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-57426 -

NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-57673 -

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 9:57 p.m.

4.8

CVSS3.1

CVE-2022-40490 -

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 7:40 p.m.

7.5

CVSS3.1

CVE-2024-39033 -

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-57392 -

Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can cause a Denial of Service (DoS) on the FTP service by sending a maliciously crafted message to the ProFTPD service port.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-57668 -

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

9.8

CVSS3.1

CVE-2025-22992 -

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: July 30, 2025, 6:12 p.m.

7.5

CVSS3.1

CVE-2024-56889 -

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

๐Ÿ“… Published: Feb. 6, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 2:06 a.m.
Total resulsts: 345234
Page 6439 of 34,524
ยซ previous page ยป next page
Filters