3.4

CVSS3.1

CVE-2025-23113 -

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert configuration. An attacker can send the victim a CSV file containing an HTML injection payload in the alert-title. Once th…

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Feb. 25, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2024-54997 -

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:18 p.m.

9.8

CVSS3.1

CVE-2024-57224 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 2:05 p.m.

9.3

CVSS3.1

CVE-2024-57823 - raptor: integer underflow when normalizing a URI with the turtle parser

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-54687 -

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 2:38 a.m.

9.8

CVSS3.1

CVE-2024-57686 -

A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: March 28, 2025, 7:17 p.m.

8

CVSS3.1

CVE-2024-57211 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.

8

CVSS3.1

CVE-2024-57228 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 2:16 p.m.

6.3

CVSS3.1

CVE-2024-57213 -

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 3:48 p.m.

4.7

CVSS3.1

CVE-2024-33299 -

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 12:39 a.m.
Total resulsts: 343920
Page 6667 of 34,392
Β« previous page Β» next page
Filters