341
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13197
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
342
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13196
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
343
|
- |
|
-
|
-
|
A vulnerability was found in donglight bookstore???????? 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. T…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-13195
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
344
|
- |
|
-
|
-
|
A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argumen…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-13194
|
2025-01-9 09:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
345
|
- |
|
-
|
-
|
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a loca…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-0283
|
2025-01-9 08:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
346
|
- |
|
-
|
-
|
Rejected reason: loading template...
New
|
-
|
CVE-2024-5610
|
2025-01-9 08:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
347
|
- |
|
-
|
-
|
Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload…
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-22145
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
348
|
- |
|
-
|
-
|
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against …
New
|
-
|
CVE-2024-54010
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
349
|
- |
|
-
|
-
|
SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82,…
New
|
CWE-601
Open Redirect
|
CVE-2024-53995
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
350
|
- |
|
-
|
-
|
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux S…
New
|
-
|
CVE-2024-52869
|
2025-01-9 06:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|