241
|
- |
|
-
|
-
|
Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.
New
|
-
|
CVE-2025-22949
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
242
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerab…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22600
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
243
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows at…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22599
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
244
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability al…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22598
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
245
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerabilit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22597
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
246
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This vulnerabili…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22596
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
247
|
- |
|
-
|
-
|
Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execut…
New
|
CWE-22 CWE-94 CWE-434
Path Traversal Code Injection Unrestricted Upload of File with Dangerous Type
|
CVE-2025-22152
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
248
|
- |
|
-
|
-
|
DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause t…
New
|
CWE-289
Authentication Bypass by Alternate Name
|
CVE-2024-56511
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
249
|
- |
|
-
|
-
|
Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.
New
|
-
|
CVE-2024-50807
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
250
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
New
|
-
|
CVE-2024-46210
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|