Total
1102 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-54728 | 2025-02-03 | N/A | 6.5 MEDIUM | ||
Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs. | |||||
CVE-2025-0970 | 2025-02-02 | 5.0 MEDIUM | 4.3 MEDIUM | ||
A vulnerability was found in Zenvia Movidesk up to 25.01.22. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /Account/Login. The manipulation of the argument ReturnUrl leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 25.01.22.245a473c54 is able to address this issue. It is recommended to upgrade the affected component. | |||||
CVE-2024-8148 | 1 Esri | 1 Portal For Arcgis | 2025-01-30 | N/A | 6.1 MEDIUM |
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 10.8.1 - 11.2 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. | |||||
CVE-2020-21038 | 1 Typecho | 1 Typecho | 2025-01-29 | N/A | 6.1 MEDIUM |
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. | |||||
CVE-2023-44308 | 1 Liferay | 1 Digital Experience Platform | 2025-01-28 | N/A | 6.1 MEDIUM |
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter. | |||||
CVE-2023-5190 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2025-01-28 | N/A | 6.1 MEDIUM |
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect parameter. | |||||
CVE-2024-56972 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56971 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56969 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56968 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload. | |||||
CVE-2024-56967 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56966 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56965 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56964 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56963 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56962 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56960 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56959 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56957 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a crafted link. | |||||
CVE-2024-56955 | 2025-01-28 | N/A | 6.5 MEDIUM | ||
An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link. |