1041
|
- |
|
-
|
-
|
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. …
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2025-24355
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1042
|
- |
|
-
|
-
|
ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute…
|
CWE-134 CWE-749
Use of Externally-Controlled Format String Exposed Dangerous Method or Function
|
CVE-2025-24359
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1043
|
- |
|
-
|
-
|
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbit…
|
-
|
CVE-2025-23222
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1044
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve…
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2025-22612
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1045
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalat…
|
CWE-862
Missing Authorization
|
CVE-2025-22611
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1046
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch t…
|
CWE-862
Missing Authorization
|
CVE-2025-22610
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1047
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach …
|
CWE-862
Missing Authorization
|
CVE-2025-22609
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1048
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke …
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2025-22608
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1049
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This affects an unknown part of the file /admin/sys/user/list. The manipula…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0701
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1050
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0700
|
2025-01-25 02:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|