7.2

CVSS3.1

CVE-2024-12912 -

An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

πŸ“… Published: Jan. 2, 2025, 9:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-13093 - code-projects Job Recruitment Seeker Profile _call_main_search_ajax.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /_parse/_call_main_search_ajax.php of the component Seeker Profile Handler. The manipulation of the argument s1 leads to sql injection. The …

πŸ“… Published: Jan. 2, 2025, 9 a.m. πŸ”„ Last Modified: April 3, 2025, 2:43 p.m.

5.3

CVSS4.0

CVE-2024-13092 - code-projects Job Recruitment Job Post search_ajax.php sql injection

A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknown code of the file /_parse/_call_job/search_ajax.php of the component Job Post Handler. The manipulation of the argument n leads to sql injection. The attack can be initiated remo…

πŸ“… Published: Jan. 2, 2025, 8:31 a.m. πŸ”„ Last Modified: April 3, 2025, 2:45 p.m.

4.7

CVSS3.1

CVE-2024-12595 - AHAthat Plugin <= 1.6 - Reflected XSS via REQUEST_URI

The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

πŸ“… Published: Jan. 2, 2025, 6 a.m. πŸ”„ Last Modified: June 12, 2025, 5:04 p.m.

5.9

CVSS3.1

CVE-2024-11357 - Goodlayers Core < 2.0.10 - Contributor+ Stored XSS

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Jan. 2, 2025, 6 a.m. πŸ”„ Last Modified: June 5, 2025, 9 p.m.

4.8

CVSS3.1

CVE-2024-11184 - WP Enabled SVG <= 0.7 - Author+ Stored XSS via SVG

The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

πŸ“… Published: Jan. 2, 2025, 6 a.m. πŸ”„ Last Modified: June 24, 2025, 12:21 a.m.

5.4

CVSS3.1

CVE-2024-56830 -

The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present.

πŸ“… Published: Jan. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2002-20002 -

The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.

πŸ“… Published: Jan. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2022-49035 - media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE

In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware will have limited this to 16, but just in case it hasn't, check for this corner case.

πŸ“… Published: Jan. 2, 2025, midnight πŸ”„ Last Modified: Oct. 29, 2025, 10:49 a.m.

4.7

CVSS3.1

CVE-2024-48197 -

Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.

πŸ“… Published: Jan. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344974
Page 6895 of 34,498
Β« previous page Β» next page
Filters