61
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthori…
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2024-55896
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
62
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justifi…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-12237
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
63
|
7.3 |
HIGH
Network
-
|
-
|
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute …
New
|
CWE-94
Code Injection
|
CVE-2024-11733
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
64
|
- |
|
-
|
-
|
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.
New
|
-
|
CVE-2025-22376
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
65
|
- |
|
-
|
-
|
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulat…
New
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-13129
|
2025-01-4 07:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
66
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/sea…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0198
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
67
|
- |
|
-
|
-
|
Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS)…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-56332
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
68
|
- |
|
-
|
-
|
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The …
New
|
-
|
CVE-2024-56410
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
69
|
- |
|
-
|
-
|
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behav…
New
|
-
|
CVE-2024-36613
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
70
|
- |
|
-
|
-
|
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
New
|
-
|
CVE-2024-35365
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|