531
|
- |
|
-
|
-
|
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potentia…
|
-
|
CVE-2023-23913
|
2025-01-9 10:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
532
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13197
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
533
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13196
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
534
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. T…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-13195
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
535
|
- |
|
-
|
-
|
A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argumen…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-13194
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
536
|
- |
|
-
|
-
|
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a loca…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-0283
|
2025-01-9 08:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
537
|
- |
|
-
|
-
|
Rejected reason: loading template...
|
-
|
CVE-2024-5610
|
2025-01-9 08:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
538
|
- |
|
-
|
-
|
Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-22145
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
539
|
- |
|
-
|
-
|
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against …
|
-
|
CVE-2024-54010
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
540
|
- |
|
-
|
-
|
SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82,…
|
CWE-601
Open Redirect
|
CVE-2024-53995
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|