641
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period
io_eventfd_do_signal() is invoked from an RCU callback, bu…
|
-
|
CVE-2025-21655
|
2025-01-20 23:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
642
|
- |
|
-
|
-
|
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature comp…
|
-
|
CVE-2024-13176
|
2025-01-20 23:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
643
|
- |
|
-
|
-
|
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmi…
|
CWE-1004 CWE-614
Sensitive Cookie Without 'HttpOnly' Flag Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2025-0479
|
2025-01-20 21:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
644
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: adapt set backend to use GC transaction API
Use the GC transaction API to replace the old and buggy gc API …
|
-
|
CVE-2023-52923
|
2025-01-20 20:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
645
|
7.2 |
HIGH
Network
|
-
|
-
|
The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary cod…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-0586
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
646
|
9.8 |
CRITICAL
Network
-
|
-
|
The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
|
CWE-89
SQL Injection
|
CVE-2025-0585
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
647
|
5.3 |
MEDIUM
Network
-
|
-
|
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-0584
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
648
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the file /add-pig.php. The manipulation of the argument p…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0582
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
649
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. This affects an unknown part of the file /chat/group/send of the component Chat History. The mani…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0581
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
650
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_ap…
|
CWE-285 CWE-863
Improper Authorization Incorrect Authorization
|
CVE-2025-0580
|
2025-01-20 12:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|