1701
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.
|
CWE-284
Improper Access Control
|
CVE-2024-22316
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1702
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
|
CWE-79
Cross-site Scripting
|
CVE-2023-52292
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1703
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
|
CWE-204
Response Discrepancy Information Exposure
|
CVE-2023-47159
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1704
|
- |
|
-
|
-
|
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_…
|
-
|
CVE-2024-57595
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1705
|
- |
|
-
|
-
|
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-bas…
|
-
|
CVE-2024-50697
|
2025-01-28 01:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1706
|
- |
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows PHP Local File Inclusion. T…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-24782
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1707
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Houzez.co Houzez. This issue affects Houzez: from n/a through 3.4.0.
|
CWE-862
Missing Authorization
|
CVE-2025-24747
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1708
|
- |
|
-
|
-
|
Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3.
|
CWE-862
Missing Authorization
|
CVE-2025-24744
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1709
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor. This issue affects RomethemeKit For Elementor: from n/a through 1.5.2.
|
CWE-862
Missing Authorization
|
CVE-2025-24743
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1710
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in WP Go Maps (formerly WP Google Maps) WP Go Maps. This issue affects WP Go Maps: from n/a through 9.0.40.
|
CWE-352
Origin Validation Error
|
CVE-2025-24742
|
2025-01-28 00:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|