8.3

CVSS3.1

CVE-2025-25206 - Incorrect input validation could allow an authenticated user to read sensitive information

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cook…

📅 Published: Feb. 14, 2025, 4:47 p.m. 🔄 Last Modified: Aug. 18, 2025, 6:23 p.m.

6.3

CVSS3.1

CVE-2025-25204 - `gh attestation verify` returns incorrect exit code during verification if no attestations are pres…

`gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation cli tool `gh attestation verify` causes it to return a zero exit status when no attestations are present. This behavior is incorrect:…

📅 Published: Feb. 14, 2025, 4:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-8893 -

Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wi‑Fi.This issue affects GW1500‑XS: 1.1.2.1.

📅 Published: Feb. 14, 2025, 4:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2024-3220 - Default mimetype known files writeable on Windows

There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file locations are writable meaning other users can create invalid files to cause MemoryError to be raised on Python runtime startup or have file extensions be interpreted as the incorrec…

📅 Published: Feb. 14, 2025, 4:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-56463 - IBM QRadar SIEM cross-site scripting

IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Feb. 14, 2025, 4:14 p.m. 🔄 Last Modified: Aug. 25, 2025, 10:33 p.m.

6.5

CVSS3.1

CVE-2024-56477 - IBM Power Hardware Management Console directory traversal

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

📅 Published: Feb. 14, 2025, 2:49 p.m. 🔄 Last Modified: Aug. 18, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2024-52895 - IBM i denial of service

IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities restriction check. A privileged bad actor can remove or otherwise impact database infrastructure files resulting in incorrect behavior of software products that rely upon the databas…

📅 Published: Feb. 14, 2025, 2:36 p.m. 🔄 Last Modified: July 3, 2025, 8:54 p.m.

9.8

CVSS3.1

CVE-2024-56180 - Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can…

📅 Published: Feb. 14, 2025, 1:34 p.m. 🔄 Last Modified: July 14, 2025, 1:07 p.m.

8.5

CVSS3.1

CVE-2024-12651 - Sensitive Data Exposure in PTT Inc.'s HGS Mobile App

Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variables.This issue affects HGS Mobile App: before 6.5.0.

📅 Published: Feb. 14, 2025, 1:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-0178 - WatchGaurd Firebox Host Header Injection Vulnerability

Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaSc…

📅 Published: Feb. 14, 2025, 1:22 p.m. 🔄 Last Modified: March 2, 2026, 7:07 p.m.
Total resulsts: 346528
Page 6460 of 34,653
« previous page » next page
Filters