6.5

CVSS3.1

CVE-2024-5872 - On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might …

On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.

📅 Published: Jan. 10, 2025, 8:25 p.m. 🔄 Last Modified: Jan. 10, 2025, 9:15 p.m.

4.3

CVSS3.1

CVE-2024-7095 - On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” i…

On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out u…

📅 Published: Jan. 10, 2025, 8:19 p.m. 🔄 Last Modified: Jan. 14, 2025, 3:15 p.m.

5.8

CVSS3.1

CVE-2024-6437 - On affected platforms running Arista EOS with one of the following features configured to redirect …

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action a…

📅 Published: Jan. 10, 2025, 8:06 p.m. 🔄 Last Modified: Jan. 10, 2025, 9:12 p.m.

9.8

CVSS3.1

CVE-2024-12847 - NETGEAR DGN setup.cgi OS Command Injection

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in…

📅 Published: Jan. 10, 2025, 7:36 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

6.1

CVSS3.1

CVE-2025-23079 - XSSes in Extension:ArticleFeedbackv5

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - ArticleFeedbackv5 extension: from 1.42.X before 1.42.2.

📅 Published: Jan. 10, 2025, 7:03 p.m. 🔄 Last Modified: Jan. 13, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2025-23078 - XSS in BreadCrumbs2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X befor…

📅 Published: Jan. 10, 2025, 5:57 p.m. 🔄 Last Modified: Jan. 13, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2024-6880 - CSRF in MegaBIP

During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.  Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt fu…

📅 Published: Jan. 10, 2025, 5:51 p.m. 🔄 Last Modified: July 12, 2025, 10:23 p.m.

8.7

CVSS4.0

CVE-2024-6662 - CSRF in MegaBIP

Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms. A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If …

📅 Published: Jan. 10, 2025, 5:50 p.m. 🔄 Last Modified: July 13, 2025, 11:22 a.m.

6.4

CVSS4.0

CVE-2025-22600 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `configuracao_doacao.php` parameter `avul…

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the avulso parameter. This vulnerability is fi…

📅 Published: Jan. 10, 2025, 3:30 p.m. 🔄 Last Modified: April 9, 2025, 6:26 p.m.

6.4

CVSS4.0

CVE-2025-22599 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.
Total resulsts: 343923
Page 6663 of 34,393
« previous page » next page
Filters