251
|
- |
|
-
|
-
|
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authen…
|
-
|
CVE-2024-57523
|
2025-02-7 05:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
252
|
- |
|
-
|
-
|
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a user-supplied paramete…
|
-
|
CVE-2025-25064
|
2025-02-7 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
253
|
- |
|
-
|
-
|
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuth…
|
-
|
CVE-2025-24860
|
2025-02-7 05:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
254
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-1019
|
2025-02-7 04:40 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
255
|
5.3 |
MEDIUM
Network
mozilla
|
firefox thunderbird
|
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affect…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2025-1018
|
2025-02-7 04:40 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
256
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird <…
|
CWE-416
Use After Free
|
CVE-2025-1012
|
2025-02-7 04:33 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefo…
|
NVD-CWE-noinfo
|
CVE-2025-1011
|
2025-02-7 04:31 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < …
|
CWE-416
Use After Free
|
CVE-2025-1010
|
2025-02-7 04:30 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259
|
9.8 |
CRITICAL
Network
mozilla
|
firefox thunderbird
|
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, …
|
CWE-416
Use After Free
|
CVE-2025-1009
|
2025-02-7 04:28 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
260
|
- |
|
-
|
-
|
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log.
|
-
|
CVE-2024-13416
|
2025-02-7 04:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|