0.0

CVE-2025-22845 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Jan. 24, 2025, 4 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

6.4

CVSS3.1

CVE-2024-11931 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.

πŸ“… Published: Jan. 24, 2025, 3:02 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 7:57 p.m.

8.7

CVSS3.1

CVE-2025-0314 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17.8 before 17.8.1. Improper rendering of certain file types lead to cross-site scripting.

πŸ“… Published: Jan. 24, 2025, 2:30 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 8:41 p.m.

8.4

CVSS3.1

CVE-2025-23222 -

An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbitrary local users to legacy D-Bus methods in the actual D-Bus services, and the actual D-Bus services…

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-50690 -

SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:02 p.m.

5.7

CVSS3.1

CVE-2024-57277 -

InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-50698 -

SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content.

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 3:35 p.m.

5.4

CVSS3.1

CVE-2024-50692 -

SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communic…

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:02 p.m.

8.1

CVSS3.1

CVE-2024-50697 -

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 4:02 p.m.

4.6

CVSS3.1

CVE-2024-57041 -

A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.

πŸ“… Published: Jan. 24, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 7:33 p.m.
Total resulsts: 347392
Page 6803 of 34,740
Β« previous page Β» next page
Filters