Show filters
349,163 Total Results
Displaying 41-50 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-57026

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.
0
Attacker Value
Unknown

CVE-2024-54820

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
0
Attacker Value
Unknown

CVE-2025-26201

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote unauthenticated attackers to bypass authentication and escalate privileges.
0
Attacker Value
Unknown

CVE-2025-26200

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
0
Attacker Value
Unknown

CVE-2025-22495

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version 3.0.4. Note - Network-M2 has been declared end-of-life in early 2024 and Network-M3 has been released as a fit-and-functional replacement.
0
Attacker Value
Unknown

CVE-2025-26803

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
0
Attacker Value
Unknown

CVE-2025-25460

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
0
Attacker Value
Unknown

CVE-2024-56897

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.
0
Attacker Value
Unknown

CVE-2025-27357

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link allows Cross Site Request Forgery. This issue affects Önceki Yazı Link: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2025-27356

Disclosure Date: February 24, 2025 (last updated February 25, 2025)
Missing Authorization vulnerability in Hardik Sticky Header On Scroll allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sticky Header On Scroll: from n/a through 1.0.
0