981
|
- |
|
-
|
-
|
In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.
|
-
|
CVE-2024-56404
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
982
|
2.8 |
LOW
Local
|
-
|
-
|
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint …
|
CWE-284
Improper Access Control
|
CVE-2024-35122
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
983
|
- |
|
-
|
-
|
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially cr…
|
-
|
CVE-2019-15690
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
984
|
- |
|
-
|
-
|
In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-24362
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
985
|
5.4 |
MEDIUM
Network
|
ayecode
|
ketchup_shortcodes
|
The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' shortcode in all versions up to, and including, 0.1.2 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13590
|
2025-01-25 03:09 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
986
|
4.3 |
MEDIUM
Network
|
quantumcloud
|
wpot
|
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'qc_wp_latest_update_check_pro' function in all versio…
|
CWE-862
Missing Authorization
|
CVE-2024-12879
|
2025-01-25 03:07 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
987
|
- |
|
-
|
-
|
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. …
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2025-24355
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
988
|
- |
|
-
|
-
|
ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute…
|
CWE-134 CWE-749
Use of Externally-Controlled Format String Exposed Dangerous Method or Function
|
CVE-2025-24359
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
989
|
- |
|
-
|
-
|
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbit…
|
-
|
CVE-2025-23222
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
990
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve…
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2025-22612
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|