6.1

CVSS3.1

CVE-2024-57026 -

TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 3, 2025, 8:15 p.m.

7.8

CVSS3.1

CVE-2023-52926 - io_uring/rw: split io_read() into a helper

In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return). This can lead to a potential use-after-free when the completion via io_rw_done runs at sepa…

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:16 p.m.

9.8

CVSS3.1

CVE-2024-56897 -

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 3, 2025, 8:15 p.m.

9.8

CVSS3.1

CVE-2024-53544 -

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-25207 - Rhcl: authpolicy callbacks result in denial of service in authorino severity

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with develo…

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-53543 -

NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-56525 -

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-57685 -

An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 4:34 p.m.

5.3

CVSS3.1

CVE-2025-26803 -

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 11:07 a.m.

7.2

CVSS3.1

CVE-2025-26200 -

SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: May 1, 2025, 4:52 p.m.
Total resulsts: 347742
Page 6509 of 34,775
Β« previous page Β» next page
Filters