1151
|
7.5 |
HIGH
Network
linuxfoundation
|
magma
|
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter funct…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-24419
|
2025-01-27 23:29 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1152
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Houzez.co Houzez. This issue affects Houzez: from n/a through 3.4.0.
|
CWE-862
Missing Authorization
|
CVE-2025-24754
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1153
|
- |
|
-
|
-
|
Path Traversal vulnerability in MORKVA Morkva UA Shipping allows PHP Local File Inclusion. This issue affects Morkva UA Shipping: from n/a through 1.0.18.
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2025-24685
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1154
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology LTL Freight Quotes – Worldwide Express Edition allows SQL Injection. This issu…
|
CWE-89
SQL Injection
|
CVE-2025-24664
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1155
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MORKVA Shipping for Nova Poshta allows SQL Injection. This issue affects Shipping for Nova Poshta…
|
CWE-89
SQL Injection
|
CVE-2025-24612
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1156
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in ThimPress FundPress allows Object Injection. This issue affects FundPress: from n/a through 2.0.6.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-24601
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1157
|
- |
|
-
|
-
|
Missing Authorization vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Store Kit Elem…
|
CWE-862
Missing Authorization
|
CVE-2025-24584
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1158
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3…
|
CWE-352
Origin Validation Error
|
CVE-2025-24533
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1159
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint allows Reflected XSS. This iss…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23792
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1160
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clodeo Shipdeo allows Reflected XSS. This issue affects Shipdeo: from n/a through 1.2.8.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23457
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|