1701
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql ????????? 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site …
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2025-1084
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1702
|
- |
|
-
|
-
|
Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
|
CWE-912
Hidden Functionality
|
CVE-2025-0675
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1703
|
- |
|
-
|
-
|
Multiple Elber products are affected by an authentication bypass
vulnerability which allows unauthorized access to the password
management functionality. Attackers can exploit this issue by
manipu…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-0674
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1704
|
3.1 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic was found in Mindskip xzs-mysql ????????? 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation l…
|
CWE-346 CWE-942
Origin Validation Error Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2025-1083
|
2025-02-7 08:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1705
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in Mindskip xzs-mysql ????????? 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the component Exam Edit Handler…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-1082
|
2025-02-7 08:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1706
|
- |
|
-
|
-
|
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special value…
|
-
|
CVE-2025-22867
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1707
|
- |
|
-
|
-
|
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw …
|
-
|
CVE-2024-57430
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1708
|
- |
|
-
|
-
|
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated a…
|
-
|
CVE-2024-57429
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1709
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations …
|
-
|
CVE-2024-57428
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1710
|
- |
|
-
|
-
|
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
|
-
|
CVE-2024-39033
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|