831
|
5.3 |
MEDIUM
Network
-
|
-
|
A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. The manipulation leads to path t…
|
CWE-23 CWE-24
Relative Path Traversal Path Traversal: '../filedir'
|
CVE-2025-1086
|
2025-02-7 11:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
832
|
9.8 |
CRITICAL
Network
-
|
-
|
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-1061
|
2025-02-7 11:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
833
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in Animati PACS up to 1.24.12.09.03. This affects an unknown part of the file /login. The manipulation of the argument p leads to cross…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-1085
|
2025-02-7 10:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
834
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql ????????? 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site …
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2025-1084
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
835
|
- |
|
-
|
-
|
Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
|
CWE-912
Hidden Functionality
|
CVE-2025-0675
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
836
|
- |
|
-
|
-
|
Multiple Elber products are affected by an authentication bypass
vulnerability which allows unauthorized access to the password
management functionality. Attackers can exploit this issue by
manipu…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-0674
|
2025-02-7 09:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
837
|
3.1 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic was found in Mindskip xzs-mysql ????????? 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation l…
|
CWE-346 CWE-942
Origin Validation Error Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2025-1083
|
2025-02-7 08:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
838
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in Mindskip xzs-mysql ????????? 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the component Exam Edit Handler…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-1082
|
2025-02-7 08:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
839
|
- |
|
-
|
-
|
On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the @executable_path, @loader_path, or @rpath special value…
|
-
|
CVE-2025-22867
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
840
|
- |
|
-
|
-
|
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw …
|
-
|
CVE-2024-57430
|
2025-02-7 07:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|