421
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension…
New
|
-
|
CVE-2025-23081
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
422
|
- |
|
-
|
-
|
A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Sect…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0464
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
423
|
- |
|
-
|
-
|
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.p…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0463
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
424
|
- |
|
-
|
-
|
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of the file /crm/weixinmp/index…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0462
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
425
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
New
|
-
|
CVE-2024-53563
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
426
|
- |
|
-
|
-
|
A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.
New
|
-
|
CVE-2024-53561
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
427
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed technical error message is returned.
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-52898
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
428
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
New
|
CWE-22 CWE-288
Path Traversal Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-13181
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
429
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
New
|
CWE-22
Path Traversal
|
CVE-2024-13180
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
430
|
- |
|
-
|
-
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
New
|
CWE-22 CWE-288
Path Traversal Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-13179
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|