551
|
- |
|
-
|
-
|
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.
Update
|
-
|
CVE-2024-13275
|
2025-01-15 03:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
552
|
- |
|
-
|
-
|
A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Sect…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0464
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
553
|
- |
|
-
|
-
|
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.p…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0463
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
554
|
- |
|
-
|
-
|
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of the file /crm/weixinmp/index…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0462
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
555
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
New
|
-
|
CVE-2024-53563
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
556
|
- |
|
-
|
-
|
A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.
New
|
-
|
CVE-2024-53561
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
557
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-52898
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
558
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
New
|
CWE-22 CWE-288
Path Traversal Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-13181
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
559
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
New
|
CWE-22
Path Traversal
|
CVE-2024-13180
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
560
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
New
|
CWE-22 CWE-288
Path Traversal Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-13179
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|