451
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gravity Master Custom Field For WP Job Manager allows Reflected XSS.This issue affects Custom Fie…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22294
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
452
|
- |
|
-
|
-
|
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding t…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-21624
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
453
|
- |
|
-
|
-
|
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which resul…
New
|
CWE-22 CWE-306
Path Traversal Missing Authentication for Critical Function
|
CVE-2025-21623
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
454
|
- |
|
-
|
-
|
ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar at any time. During deletion, ClipBucket checks …
New
|
CWE-22
Path Traversal
|
CVE-2025-21622
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
455
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical. This issue affects some unknown processing of the file /process_login.php. The manipulation of the argu…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0298
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
456
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. The manipulation of the argument id…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0297
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
457
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through 1.4.…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-56056
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
458
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rezgo Rezgo allows PHP Local File Inclusion.This issue affects Rezgo: from n/a…
New
|
CWE-98 CWE-829
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2024-53800
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
459
|
- |
|
-
|
-
|
An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.
New
|
-
|
CVE-2024-53345
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
460
|
- |
|
-
|
-
|
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptograp…
New
|
CWE-223
|
CVE-2024-52813
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|