8.3

CVSS3.1

CVE-2025-0291 -

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

📅 Published: Jan. 8, 2025, 6:42 p.m. 🔄 Last Modified: Feb. 11, 2025, 3:16 p.m.

9.4

CVSS4.0

CVE-2025-22141 - WeGIA SQL Injection (Blind Time-Based) endpoint 'verificar_recursos_cargo.php' parameter 'cargo'

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity…

📅 Published: Jan. 8, 2025, 6:27 p.m. 🔄 Last Modified: April 9, 2025, 6:28 p.m.

6.4

CVSS4.0

CVE-2025-22139 - WeGIA Cross-Site Scripting (XSS) Reflected endpoint `configuracao_geral.php` parameter `msg`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixe…

📅 Published: Jan. 8, 2025, 6:26 p.m. 🔄 Last Modified: April 9, 2025, 6:28 p.m.

9.4

CVSS4.0

CVE-2025-22140 - WeGIA SQL Injection (Blind Time-Based) endpoint 'dependente_listar_um.php' parameter 'id_dependente'

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confident…

📅 Published: Jan. 8, 2025, 6:25 p.m. 🔄 Last Modified: April 9, 2025, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-21111 -

Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

📅 Published: Jan. 8, 2025, 5:38 p.m. 🔄 Last Modified: Jan. 24, 2025, 7:11 p.m.

7.8

CVSS3.1

CVE-2023-35685 -

In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Jan. 8, 2025, 5:35 p.m. 🔄 Last Modified: Jan. 31, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2024-6350 - EmberZNet malformed MAC layer packet leads to denial of service

A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.

📅 Published: Jan. 8, 2025, 5:12 p.m. 🔄 Last Modified: Jan. 8, 2025, 6:15 p.m.

4.8

CVSS4.0

CVE-2024-13187 - Kingsoft WPS Office TCC code injection

A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit h…

📅 Published: Jan. 8, 2025, 4:31 p.m. 🔄 Last Modified: July 12, 2025, 10:31 p.m.

5.4

CVSS3.1

CVE-2025-20168 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Jan. 8, 2025, 4:19 p.m. 🔄 Last Modified: July 23, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-20167 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-suppl…

📅 Published: Jan. 8, 2025, 4:19 p.m. 🔄 Last Modified: July 23, 2025, 4:11 p.m.
Total resulsts: 343744
Page 6679 of 34,375
« previous page » next page
Filters