991
|
- |
|
-
|
-
|
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0.
Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.
|
-
|
CVE-2024-45479
|
2025-01-28 06:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
992
|
- |
|
-
|
-
|
Issue summary: A timing side-channel which could potentially allow recovering
the private key exists in the ECDSA signature computation.
Impact summary: A timing side-channel in ECDSA signature comp…
|
-
|
CVE-2024-13176
|
2025-01-28 06:15 |
2025-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
993
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation leads to heap-based…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2025-0751
|
2025-01-28 05:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
994
|
- |
|
-
|
-
|
Network access can be used to execute arbitrary code with elevated privileges.
This
issue affects FLXEON 9.3.4 and older.
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-48841
|
2025-01-28 05:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
995
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. The manipulation leads to des…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2025-0734
|
2025-01-28 04:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
996
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in buil…
|
-
|
CVE-2025-24368
|
2025-01-28 04:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
997
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web ro…
|
-
|
CVE-2025-24367
|
2025-01-28 04:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
998
|
9.8 |
CRITICAL
Network
sonicwall
|
sma8200v sma6200_firmware sma6210_firmware sma7200_firmware sma7210_firmware sra_ex6000_firmware sra_ex7000_firmware sra_ex9000_firmware
|
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific condit…
|
-
|
CVE-2025-23006
|
2025-01-28 03:41 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
999
|
- |
|
-
|
-
|
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim o…
|
CWE-284
Improper Access Control
|
CVE-2025-24365
|
2025-01-28 03:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1000
|
- |
|
-
|
-
|
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code …
|
CWE-74
Injection
|
CVE-2025-24364
|
2025-01-28 03:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|