4301
|
4.0 |
MEDIUM
Local
|
-
|
-
|
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
|
CWE-471
Modification of Assumed-Immutable Data (MAID)
|
CVE-2024-51462
|
2025-01-17 12:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4302
|
- |
|
-
|
-
|
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
|
-
|
CVE-2024-12806
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4303
|
- |
|
-
|
-
|
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
|
-
|
CVE-2024-12805
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4304
|
- |
|
-
|
-
|
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
|
-
|
CVE-2024-12803
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4305
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../…
|
CWE-22
Path Traversal
|
CVE-2024-52363
|
2025-01-17 11:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4306
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-21325
|
2025-01-17 10:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4307
|
- |
|
-
|
-
|
Fuji Electric Alpha5 SMART
is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-34579
|
2025-01-17 10:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4308
|
- |
|
-
|
-
|
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23201
|
2025-01-17 08:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4309
|
- |
|
-
|
-
|
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 …
|
CWE-79
Cross-site Scripting
|
CVE-2025-23200
|
2025-01-17 08:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4310
|
- |
|
-
|
-
|
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `/ajax_form.php` -> param: descr. Librenms version up to 24.10.1 …
|
CWE-79
Cross-site Scripting
|
CVE-2025-23199
|
2025-01-17 08:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|