341
|
- |
|
-
|
-
|
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute …
New
|
-
|
CVE-2024-57487
|
2025-01-14 05:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
342
|
- |
|
-
|
-
|
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 512…
New
|
-
|
CVE-2024-48883
|
2025-01-14 05:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
343
|
- |
|
-
|
-
|
An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.
New
|
-
|
CVE-2024-46919
|
2025-01-14 05:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
344
|
- |
|
-
|
-
|
The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used…
New
|
-
|
CVE-2024-12587
|
2025-01-14 05:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
345
|
- |
|
-
|
-
|
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
New
|
-
|
CVE-2024-54687
|
2025-01-14 05:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
346
|
7.5 |
HIGH
Network
huawei
|
harmonyos
|
Vulnerability of input parameters not being verified in the widget framework module
Impact: Successful exploitation of this vulnerability may affect availability.
Update
|
NVD-CWE-noinfo
|
CVE-2024-56437
|
2025-01-14 04:27 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
347
|
5.9 |
MEDIUM
Network
|
huawei
|
harmonyos
|
Race condition vulnerability in the distributed notification module
Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
Update
|
CWE-362
Race Condition
|
CVE-2024-54120
|
2025-01-14 04:27 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
348
|
- |
|
-
|
-
|
An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not…
New
|
-
|
CVE-2024-46921
|
2025-01-14 04:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
349
|
- |
|
-
|
-
|
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint
New
|
-
|
CVE-2024-46310
|
2025-01-14 04:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
350
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).…
New
|
-
|
CVE-2025-23078
|
2025-01-14 04:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|