601
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Trimble SPS851 488.01. Affected by this issue is some unknown functionality of the component Receiver Status Identity Tab. The …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0219
|
2025-01-5 15:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
602
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanage…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13133
|
2025-01-5 14:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
603
|
- |
-
|
-
|
-
|
A vulnerability classified as problematic was found in Emlog Pro up to 2.4.3. This vulnerability affects unknown code of the file /admin/article.php of the component Subpage Handler. The manipulation…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13132
|
2025-01-5 14:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
604
|
- |
-
|
-
|
-
|
A vulnerability classified as problematic has been found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. This affects an unknown part of the file /web_caps/webC…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2024-13131
|
2025-01-5 12:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
605
|
- |
-
|
-
|
-
|
A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality…
|
CWE-23 CWE-24
Relative Path Traversal Path Traversal: '../filedir'
|
CVE-2024-13130
|
2025-01-5 10:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
606
|
- |
-
|
-
|
-
|
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as problematic. This issue affects some unknown processing of the file /admin/index.php. The manipulation of…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0214
|
2025-01-5 02:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
607
|
- |
-
|
-
|
-
|
A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forms/update_forms.php?action=change_pic2&…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0213
|
2025-01-5 02:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
608
|
- |
-
|
-
|
-
|
A vulnerability was found in Campcodes Student Grading System 1.0. It has been classified as critical. This affects an unknown part of the file /view_students.php. The manipulation of the argument id…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0212
|
2025-01-5 01:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
609
|
- |
-
|
-
|
-
|
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipula…
|
CWE-73
External Control of File Name or Path
|
CVE-2025-0211
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
610
|
6.5 |
MEDIUM
Network
-
|
-
|
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure sta…
|
CWE-544
Missing Standardized Error Handling Mechanism
|
CVE-2024-41768
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
611
|
7.3 |
HIGH
Network
-
|
-
|
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to vi…
|
CWE-89
SQL Injection
|
CVE-2024-41767
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
612
|
7.5 |
HIGH
Network
-
|
-
|
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-41766
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
613
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request contain…
|
CWE-22
Path Traversal
|
CVE-2024-41765
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
614
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-41763
|
2025-01-5 00:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
615
|
- |
-
|
-
|
-
|
A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?act…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0210
|
2025-01-4 23:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
616
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /summary.php. The manipulation of the argument tid leads …
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0208
|
2025-01-4 22:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
617
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/login.php. The man…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0207
|
2025-01-4 22:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
618
|
- |
-
|
-
|
-
|
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew…
|
-
|
CVE-2024-13042
|
2025-01-4 22:15 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
619
|
- |
-
|
-
|
-
|
A vulnerability classified as critical was found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation lead…
|
CWE-284 CWE-266
Improper Access Control Incorrect Privilege Assignment
|
CVE-2025-0206
|
2025-01-4 21:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
620
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Multi Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. Th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12475
|
2025-01-4 21:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
621
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a funct…
|
CWE-352
Origin Validation Error
|
CVE-2024-12279
|
2025-01-4 21:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
622
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /w…
|
CWE-89
SQL Injection
|
CVE-2024-12195
|
2025-01-4 21:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
623
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12221
|
2025-01-4 19:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
624
|
- |
-
|
-
|
-
|
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to s…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0205
|
2025-01-4 18:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
625
|
9.9 |
CRITICAL
Network
|
-
|
-
|
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. …
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2024-12583
|
2025-01-4 18:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
626
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and includi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11930
|
2025-01-4 18:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
627
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argument …
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0204
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
628
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12701
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
629
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t…
|
CWE-352
Origin Validation Error
|
CVE-2024-12545
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
630
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including,…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12047
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
631
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11974
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
632
|
8.8 |
HIGH
Network
|
-
|
-
|
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replac…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10932
|
2025-01-4 17:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
633
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Student Management System 1.0. It has been declared as critical. This vulnerability affects the function showSubject1 of the file /config/DbFunction.php. Th…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0203
|
2025-01-4 16:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
634
|
- |
-
|
-
|
-
|
A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the file /REPORTS/REPORTS_SHOW_FILE.jsp. The manipulation of the argument FilePath le…
|
CWE-73
External Control of File Name or Path
|
CVE-2025-0202
|
2025-01-4 14:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
635
|
- |
-
|
-
|
-
|
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/update…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0201
|
2025-01-4 13:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
636
|
- |
-
|
-
|
-
|
A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0200
|
2025-01-4 12:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
637
|
- |
-
|
-
|
-
|
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allow…
|
-
|
CVE-2025-22389
|
2025-01-4 12:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
638
|
- |
-
|
-
|
-
|
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewal…
|
-
|
CVE-2024-3393
|
2025-01-4 11:00 |
2024-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
639
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management System 1.0. Affected is an unknown function of the file /user/minus_cart.php. The…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0199
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
640
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM PowerHA SystemMirror for i 7.4 and 7.5
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to …
|
-
|
CVE-2024-55897
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
641
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthori…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2024-55896
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
642
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justifi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-12237
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
643
|
7.3 |
HIGH
Network
-
|
-
|
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute …
|
CWE-94
Code Injection
|
CVE-2024-11733
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
644
|
- |
-
|
-
|
-
|
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.
|
-
|
CVE-2025-22376
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
645
|
- |
-
|
-
|
-
|
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulat…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-13129
|
2025-01-4 07:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
646
|
- |
-
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/sea…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0198
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
647
|
- |
-
|
-
|
-
|
Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS)…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-56332
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
648
|
- |
-
|
-
|
-
|
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The …
|
-
|
CVE-2024-56410
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
649
|
- |
-
|
-
|
-
|
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behav…
|
-
|
CVE-2024-36613
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
650
|
- |
-
|
-
|
-
|
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
|
-
|
CVE-2024-35365
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|