921
|
10.0 |
CRITICAL
Network
-
|
-
|
Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monit…
|
CWE-566
|
CVE-2024-13152
|
2025-02-14 22:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
922
|
- |
|
-
|
-
|
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by send…
|
CWE-799
Improper Control of Interaction Frequency
|
CVE-2025-26524
|
2025-02-14 21:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
923
|
- |
|
-
|
-
|
This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this v…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-26523
|
2025-02-14 21:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
924
|
- |
|
-
|
-
|
This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this…
|
CWE-302
Authentication Bypass by Assumed-Immutable Data
|
CVE-2025-26522
|
2025-02-14 21:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
925
|
- |
|
-
|
-
|
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain …
|
-
|
CVE-2025-1099
|
2025-02-14 21:15 |
2025-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
926
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied paramete…
|
CWE-89
SQL Injection
|
CVE-2025-0821
|
2025-02-14 20:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
927
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers…
|
CWE-23
Relative Path Traversal
|
CVE-2024-13791
|
2025-02-14 20:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
928
|
- |
|
-
|
-
|
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually craf…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-52577
|
2025-02-14 19:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
929
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.11.2 due…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13735
|
2025-02-14 19:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
930
|
- |
|
-
|
-
|
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-admin users to access sensitive information about AgentX Manager in a Logpoint de…
|
-
|
CVE-2025-26789
|
2025-02-14 17:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|