9.8

CVSS3.1

CVE-2024-56525 -

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-57685 -

An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 4:34 p.m.

5.3

CVSS3.1

CVE-2025-26803 -

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: July 13, 2025, 11:07 a.m.

7.2

CVSS3.1

CVE-2025-26200 -

SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 4:52 p.m.

6

CVSS3.1

CVE-2025-23017 -

WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-26201 -

Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-25513 -

Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 5:15 p.m.

4.8

CVSS3.1

CVE-2025-25460 -

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to โ€ฆ

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 8:14 p.m.

7.5

CVSS3.1

CVE-2025-1634 - Io.quarkus:quarkus-resteasy: memory leak in quarkus resteasy classic when client requests timeout

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2026, noon

9.8

CVSS3.1

CVE-2024-54820 -

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

๐Ÿ“… Published: Feb. 24, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347746
Page 6510 of 34,775
ยซ previous page ยป next page
Filters