4.3

CVSS3.1

CVE-2024-57969 -

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 3 p.m.

6.5

CVSS3.1

CVE-2024-57725 -

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-25988 -

Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: April 18, 2025, 1:53 a.m.

7.5

CVSS3.1

CVE-2025-25994 -

SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:43 p.m.

4.5

CVSS3.1

CVE-2025-26791 - dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 7, 2025, 8:56 p.m.

5.6

CVSS3.1

CVE-2025-26158 -

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: June 6, 2025, 5:58 p.m.

8.8

CVSS3.1

CVE-2024-57778 -

An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-26156 -

A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: April 2, 2025, 6:49 p.m.

5.1

CVSS3.1

CVE-2025-25992 -

SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: May 2, 2025, 7:44 p.m.

6.9

CVSS4.0

CVE-2025-26789 -

An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint deployment.

๐Ÿ“… Published: Feb. 14, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346563
Page 6473 of 34,657
ยซ previous page ยป next page
Filters