1701
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue is some unknown functionality of the file /api/front/search/books. The manipulat…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-1154
|
2025-02-11 05:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1702
|
- |
|
-
|
-
|
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injectio…
|
-
|
CVE-2024-57178
|
2025-02-11 05:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1703
|
3.1 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory cor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2025-1153
|
2025-02-11 04:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1704
|
9.8 |
CRITICAL
Network
-
|
-
|
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and includi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13011
|
2025-02-11 04:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1705
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on the 'search_…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13010
|
2025-02-11 04:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1706
|
- |
|
-
|
-
|
Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-25188
|
2025-02-11 03:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1707
|
3.1 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is…
|
CWE-404 CWE-401
Improper Resource Shutdown or Release Missing Release of Memory after Effective Lifetime
|
CVE-2025-1152
|
2025-02-11 03:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1708
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2024-57407
|
2025-02-11 03:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1709
|
- |
|
-
|
-
|
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
|
-
|
CVE-2024-54954
|
2025-02-11 03:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1710
|
- |
|
-
|
-
|
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.
|
-
|
CVE-2024-48170
|
2025-02-11 03:15 |
2025-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|