981
|
- |
|
-
|
-
|
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://githu…
|
-
|
CVE-2021-3978
|
2025-01-29 19:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
982
|
- |
|
-
|
-
|
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that…
|
-
|
CVE-2024-57965
|
2025-01-29 19:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
983
|
- |
|
-
|
-
|
Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory outside the bounds of …
|
-
|
CVE-2024-7695
|
2025-01-29 17:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
984
|
7.2 |
HIGH
Network
-
|
-
|
The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-13696
|
2025-01-29 17:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
985
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up t…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0804
|
2025-01-29 13:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
986
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0806
|
2025-01-29 12:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
987
|
- |
|
-
|
-
|
The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, …
|
CWE-79
Cross-site Scripting
|
CVE-2025-23362
|
2025-01-29 11:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
988
|
7.3 |
HIGH
Network
-
|
-
|
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0803
|
2025-01-29 11:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
989
|
7.3 |
HIGH
Network
-
|
-
|
A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of …
|
CWE-284 CWE-266
Improper Access Control Incorrect Privilege Assignment
|
CVE-2025-0802
|
2025-01-29 11:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
990
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0800
|
2025-01-29 11:15 |
2025-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|