9.8

CVSS3.1

CVE-2024-57225 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 2:14 p.m.

8.8

CVSS3.1

CVE-2024-54996 -

MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:18 p.m.

4.7

CVSS3.1

CVE-2025-23111 -

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field name, which redirects them to a phishing website. T…

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Feb. 25, 2025, 4:16 p.m.

4

CVSS3.1

CVE-2025-23022 - freetype: signed integer overflow in cf2_doFlex

FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

6.3

CVSS3.1

CVE-2024-57222 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 1:59 p.m.

5.9

CVSS3.1

CVE-2024-54849 -

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 4:54 p.m.

5.9

CVSS3.1

CVE-2024-54847 -

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5:17 p.m.

8

CVSS3.1

CVE-2024-57227 -

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

πŸ“… Published: Jan. 10, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 2:16 p.m.

0.0

CVE-2024-13324 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a reservation duplicate of 2024-13362. Notes: All CVE users should reference 2024-13362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accident…

πŸ“… Published: Jan. 9, 2025, 11:11 p.m. πŸ”„ Last Modified: Jan. 13, 2025, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-21380 - Azure Marketplace SaaS Resources Information Disclosure Vulnerability

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

πŸ“… Published: Jan. 9, 2025, 10:32 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 7:56 p.m.
Total resulsts: 343919
Page 6668 of 34,392
Β« previous page Β» next page
Filters