9.8

CVSS3.1

CVE-2025-22992 -

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: July 30, 2025, 6:12 p.m.

7.5

CVSS3.1

CVE-2024-56889 -

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 2:06 a.m.

7.5

CVSS3.1

CVE-2024-36558 -

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of Sensitive Information due to lack of encryption in device-server communication.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-55241 -

An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the modelsbyom.py component.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-57672 -

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 9:58 p.m.

6.1

CVSS3.1

CVE-2024-57427 -

PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

πŸ“… Published: Feb. 6, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:13 a.m.

4.3

CVSS3.1

CVE-2024-49800 - IBM ApplinX Information Disclosure

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

πŸ“… Published: Feb. 5, 2025, 11:55 p.m. πŸ”„ Last Modified: Feb. 22, 2025, 10:07 p.m.

4.3

CVSS3.1

CVE-2024-49798 - IBM ApplinX Information Disclosure

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

πŸ“… Published: Feb. 5, 2025, 11:50 p.m. πŸ”„ Last Modified: Feb. 22, 2025, 10:06 p.m.

5.9

CVSS3.1

CVE-2024-49797 - IBM ApplinX Information Disclosure

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

πŸ“… Published: Feb. 5, 2025, 11:48 p.m. πŸ”„ Last Modified: Feb. 22, 2025, 10:06 p.m.

5.4

CVSS3.1

CVE-2024-49796 - IBM ApplinX Clickjacking

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.

πŸ“… Published: Feb. 5, 2025, 11:46 p.m. πŸ”„ Last Modified: Feb. 22, 2025, 10:05 p.m.
Total resulsts: 345256
Page 6442 of 34,526
Β« previous page Β» next page
Filters