541
|
- |
|
-
|
-
|
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on …
|
CWE-459
Incomplete Cleanup
|
CVE-2025-0473
|
2025-01-16 22:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
542
|
- |
|
-
|
-
|
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine…
|
CWE-200
Information Exposure
|
CVE-2025-0472
|
2025-01-16 22:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
543
|
- |
|
-
|
-
|
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, bein…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0471
|
2025-01-16 22:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
544
|
- |
|
-
|
-
|
In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a …
|
-
|
CVE-2025-23013
|
2025-01-16 22:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
545
|
7.5 |
HIGH
Network
-
|
-
|
An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-25108
|
2025-01-16 20:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
546
|
- |
|
-
|
-
|
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 th…
|
CWE-1390
Weak Authentication
|
CVE-2024-50563
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
547
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shortcode in all versions up to, and including, 1.2.9 due to insufficient input san…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13387
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
548
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() functi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13355
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
549
|
5.3 |
MEDIUM
Network
-
|
-
|
The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability check on the fw_upload_file AJAX action in all versions up to, and including, 1.…
|
CWE-862
Missing Authorization
|
CVE-2024-12427
|
2025-01-16 19:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
550
|
- |
|
-
|
-
|
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiRecorder versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiWeb versions 7.6.0, 7.4.0 through 7.…
|
CWE-22
Path Traversal
|
CVE-2024-48885
|
2025-01-16 18:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|