861
|
- |
|
-
|
-
|
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.
|
-
|
CVE-2025-22376
|
2025-01-4 08:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
862
|
- |
|
-
|
-
|
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulat…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2024-13129
|
2025-01-4 07:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
863
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/sea…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0198
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
864
|
- |
|
-
|
-
|
Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS)…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-56332
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
865
|
- |
|
-
|
-
|
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The …
|
-
|
CVE-2024-56410
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
866
|
- |
|
-
|
-
|
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behav…
|
-
|
CVE-2024-36613
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
867
|
- |
|
-
|
-
|
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
|
-
|
CVE-2024-35365
|
2025-01-4 06:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
868
|
7.8 |
HIGH
Local
|
watchguard
|
panda_dome
|
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An atta…
|
CWE-59
Link Following
|
CVE-2024-13043
|
2025-01-4 05:56 |
2024-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
869
|
- |
|
-
|
-
|
A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipul…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0197
|
2025-01-4 05:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
870
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation o…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0196
|
2025-01-4 04:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|