3.1

CVSS3.1

CVE-2024-51472 - IBM DevOps Deploy / IBM UrbanCode Deploy HTML injection

IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

πŸ“… Published: Jan. 6, 2025, 4:38 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 9:33 p.m.

7.5

CVSS3.1

CVE-2025-21618 - NiceGUI On Air authentication issue

NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. This vulnerability is fixed in 2.9.1.

πŸ“… Published: Jan. 6, 2025, 4:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-21615 - AAT allows data exfiltration by other apps installed on the same device

AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to data exfiltration from malicious apps installed on the same device.

πŸ“… Published: Jan. 6, 2025, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-21614 - go-git clients vulnerable to DoS via maliciously crafted Git server replies

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git serve…

πŸ“… Published: Jan. 6, 2025, 4:20 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:24 p.m.

9.2

CVSS4.0

CVE-2025-21613 - go-git has an Argument Injection via the URL field

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happen…

πŸ“… Published: Jan. 6, 2025, 4:13 p.m. πŸ”„ Last Modified: April 17, 2025, 2:33 a.m.

6.4

CVSS3.1

CVE-2024-31914 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

πŸ“… Published: Jan. 6, 2025, 4:02 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-31913 - IBM Sterling B2B Integrator cross-site scripting

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials…

πŸ“… Published: Jan. 6, 2025, 4:02 p.m. πŸ”„ Last Modified: March 5, 2025, 4:02 p.m.

8.6

CVSS3.1

CVE-2025-21612 - Cross-site Scripting in TabberTransclude in Extension:TabberNeue

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2.

πŸ“… Published: Jan. 6, 2025, 3:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-21611 - tgstation-server's role authorization incorrectly OR'd with user's enabled status

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all, authorized actions rega…

πŸ“… Published: Jan. 6, 2025, 3:38 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 1:17 p.m.

6.9

CVSS4.0

CVE-2025-21604 - LangChain4j-AIDeepin Using MD5 to Hash files may cause file upload conflicts

LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

πŸ“… Published: Jan. 6, 2025, 3:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346624
Page 7016 of 34,663
Β« previous page Β» next page
Filters