1151
|
- |
|
-
|
-
|
go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2025-25199
|
2025-02-13 03:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1152
|
- |
|
-
|
-
|
mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionality allows an attacker to manipulate the …
|
CWE-601
Open Redirect
|
CVE-2025-25198
|
2025-02-13 03:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1153
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument $_…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-1213
|
2025-02-13 03:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1154
|
- |
|
-
|
-
|
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
|
CWE-36
Absolute Path Traversal
|
CVE-2024-6097
|
2025-02-13 03:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1155
|
6.5 |
MEDIUM
Network
|
ibm
|
applinx
|
IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-49800
|
2025-02-13 02:58 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1156
|
- |
|
-
|
-
|
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.
|
-
|
CVE-2025-25746
|
2025-02-13 02:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1157
|
- |
|
-
|
-
|
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authent…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-25182
|
2025-02-13 02:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1158
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-0818. Reason: This candidate is a reservation duplicate of CVE-2025-0818. Notes: All CVE users should reference CV…
|
-
|
CVE-2025-0925
|
2025-02-13 02:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1159
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-0818. Reason: This candidate is a reservation duplicate of CVE-2025-0818. Notes: All CVE users should reference CV…
|
-
|
CVE-2025-0919
|
2025-02-13 02:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1160
|
- |
|
-
|
-
|
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or comman…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2024-11628
|
2025-02-13 02:15 |
2025-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|