571
|
- |
|
-
|
-
|
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls…
|
-
|
CVE-2024-53934
|
2025-01-9 02:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
572
|
- |
|
-
|
-
|
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwri…
|
CWE-20 CWE-434
Improper Input Validation Unrestricted Upload of File with Dangerous Type
|
CVE-2025-22137
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
573
|
- |
|
-
|
-
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and Enable…
|
CWE-94
Code Injection
|
CVE-2025-22136
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
574
|
- |
|
-
|
-
|
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious …
|
CWE-22
Path Traversal
|
CVE-2025-22130
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
575
|
- |
|
-
|
-
|
RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-55656
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
576
|
4.8 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics infor…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-20126
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
577
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks agains…
|
CWE-79
Cross-site Scripting
|
CVE-2025-20123
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
578
|
- |
|
-
|
-
|
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL q…
|
-
|
CVE-2024-55517
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
579
|
- |
|
-
|
-
|
RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT…
|
CWE-190 CWE-122
Integer Overflow or Wraparound Heap-based Buffer Overflow
|
CVE-2024-51737
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
580
|
- |
|
-
|
-
|
RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially c…
|
CWE-190 CWE-122
Integer Overflow or Wraparound Heap-based Buffer Overflow
|
CVE-2024-51480
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|