4.7

CVSS3.1

CVE-2024-33297 -

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: July 3, 2025, 12:40 a.m.

6.1

CVSS3.1

CVE-2025-23112 -

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, it triggers the XSS payload.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 25, 2025, 4:14 p.m.

9.8

CVSS3.1

CVE-2025-22946 -

Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: April 9, 2025, 6:35 p.m.

6.1

CVSS3.1

CVE-2024-50807 -

Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: April 16, 2025, 8:45 p.m.

4.7

CVSS3.1

CVE-2024-54910 -

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 14, 2025, 4:15 p.m.

6.3

CVSS3.1

CVE-2024-57214 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 3:47 p.m.

9.3

CVSS3.1

CVE-2025-23016 -

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.1

CVSS3.1

CVE-2024-33298 -

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: July 3, 2025, 12:39 a.m.

9.8

CVSS3.1

CVE-2024-29970 -

Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 14, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2024-57687 -

An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.

๐Ÿ“… Published: Jan. 10, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 7:16 p.m.
Total resulsts: 343921
Page 6665 of 34,393
ยซ previous page ยป next page
Filters