6

CVSS3.1

CVE-2025-23017 -

WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-26201 -

Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-25513 -

Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 14, 2025, 5:15 p.m.

4.8

CVSS3.1

CVE-2025-25460 -

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to …

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 8:14 p.m.

7.5

CVSS3.1

CVE-2025-1634 - Io.quarkus:quarkus-resteasy: memory leak in quarkus resteasy classic when client requests timeout

A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 22, 2026, noon

9.8

CVSS3.1

CVE-2024-54820 -

XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-25209 - Rhcl: sharedsecretref can be used to leak secrets severity

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead of copying it to the referred namespace. This creates space for a malicious actor with a developer persona access to leak those…

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-25208 - Rhcl: authorino denial of service through authpolicy with sharedsecretref severity

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-22974 -

SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 4:36 p.m.

6.5

CVSS3.1

CVE-2024-53542 -

Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.

πŸ“… Published: Feb. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347802
Page 6516 of 34,781
Β« previous page Β» next page
Filters