7.5

CVSS3.1

CVE-2024-46242 -

An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-50659 -

Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 20, 2025, 6:06 p.m.

9.8

CVSS3.1

CVE-2024-50658 -

Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:17 a.m.

8.8

CVSS3.1

CVE-2022-45185 -

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:38 p.m.

7.8

CVSS3.1

CVE-2024-55413 -

A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information di…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-35532 -

An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-55008 -

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the atta…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 12:19 a.m.

7.5

CVSS3.1

CVE-2024-46602 -

An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 16, 2025, 3:13 p.m.

7.9

CVSS3.1

CVE-2024-40427 -

Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 20, 2025, 6:04 p.m.

6.1

CVSS3.1

CVE-2024-55218 -

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 5 p.m.
Total resulsts: 346614
Page 7011 of 34,662
Β« previous page Β» next page
Filters