281
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the inten…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-38317
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
282
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-38316
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
283
|
- |
|
-
|
-
|
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. Thi…
New
|
-
|
CVE-2025-23419
|
2025-02-6 05:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
284
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privi…
New
|
CWE-269
Improper Privilege Management
|
CVE-2025-24805
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
285
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentat…
New
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2025-24804
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
286
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentat…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-24803
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
287
|
- |
|
-
|
-
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload a file containing code that when executed …
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-24372
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
288
|
- |
|
-
|
-
|
An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker t…
New
|
-
|
CVE-2024-53943
|
2025-02-6 04:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
289
|
5.4 |
MEDIUM
Network
|
qodeinteractive
|
qi_addons_for_elementor
|
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter in all versions up to, and including, 1.8.7 due to insufficient input sanitiza…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13699
|
2025-02-6 03:33 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
290
|
- |
|
-
|
-
|
When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluat…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2025-24497
|
2025-02-6 03:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|