9.8

CVSS3.1

CVE-2024-50660 -

File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 6:47 p.m.

7.8

CVSS3.1

CVE-2024-55412 -

A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disc…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-48245 -

Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which a…

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 4:06 p.m.

8.1

CVSS3.1

CVE-2022-45186 -

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:33 p.m.

9.8

CVSS3.1

CVE-2022-41572 -

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 3:10 p.m.

7.8

CVSS3.1

CVE-2024-55410 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2025, 2:15 a.m.

5.4

CVSS3.1

CVE-2024-44450 -

Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.

πŸ“… Published: Jan. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-20007 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Jan. 6, 2025, 11:39 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:12 p.m.

7.5

CVSS3.1

CVE-2025-21620 - Deno's authorization headers not dropped when redirecting cross-origin

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a request with the Authorization header to one domain, and the response asks to redirect to a different domain, Deno'sfetch() redirect handling creates a follow-up redirect request that keeps the original …

πŸ“… Published: Jan. 6, 2025, 10:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-21616 - Plane has a Cross-site scripting (XSS) via SVG image upload

Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' b…

πŸ“… Published: Jan. 6, 2025, 9:22 p.m. πŸ”„ Last Modified: June 20, 2025, 6:08 p.m.
Total resulsts: 346617
Page 7013 of 34,662
Β« previous page Β» next page
Filters