411
|
- |
|
-
|
-
|
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The manipulation of the arg…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0400
|
2025-01-13 08:15 |
2025-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
412
|
- |
|
-
|
-
|
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0399
|
2025-01-13 08:15 |
2025-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
413
|
- |
|
-
|
-
|
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel t…
New
|
-
|
CVE-2024-42181
|
2025-01-13 07:15 |
2025-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
414
|
- |
|
-
|
-
|
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special chara…
New
|
-
|
CVE-2024-42180
|
2025-01-13 07:15 |
2025-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
415
|
- |
|
-
|
-
|
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API/2.0 as the server's name & version.
New
|
-
|
CVE-2024-42179
|
2025-01-13 07:15 |
2025-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
416
|
- |
|
-
|
-
|
A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /resources/..;/inport/updateInport of the…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0398
|
2025-01-12 23:15 |
2025-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
417
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
New
|
CWE-780
|
CVE-2024-51456
|
2025-01-12 23:15 |
2025-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
418
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads t…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0397
|
2025-01-12 22:15 |
2025-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
419
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConnection of the component XPC Service. The manipulat…
New
|
CWE-77 CWE-74
Command Injection Injection
|
CVE-2025-0396
|
2025-01-12 21:15 |
2025-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
420
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary J…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-49785
|
2025-01-12 11:15 |
2025-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|