331
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially le…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56470
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
332
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within…
|
CWE-80
Basic XSS
|
CVE-2024-38318
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
333
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38317
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
334
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-38316
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
335
|
- |
|
-
|
-
|
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. Thi…
|
-
|
CVE-2025-23419
|
2025-02-6 05:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
336
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privi…
|
CWE-269
Improper Privilege Management
|
CVE-2025-24805
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
337
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentat…
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2025-24804
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
338
|
- |
|
-
|
-
|
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentat…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24803
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
339
|
- |
|
-
|
-
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload a file containing code that when executed …
|
CWE-79
Cross-site Scripting
|
CVE-2025-24372
|
2025-02-6 04:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
340
|
- |
|
-
|
-
|
An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker t…
|
-
|
CVE-2024-53943
|
2025-02-6 04:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|