311
|
- |
|
-
|
-
|
A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. The manipulation of the argum…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0334
|
2025-01-9 15:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
312
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigg…
New
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2024-6324
|
2025-01-9 15:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
313
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to …
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0333
|
2025-01-9 14:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
314
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of th…
New
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2025-0331
|
2025-01-9 14:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
315
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php …
New
|
CWE-77 CWE-74
Command Injection Injection
|
CVE-2025-0328
|
2025-01-9 14:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
316
|
7.4 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging …
New
|
CWE-385
Covert Timing Channel
|
CVE-2025-0306
|
2025-01-9 13:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
317
|
5.6 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-56827
|
2025-01-9 13:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
318
|
5.6 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2024-56826
|
2025-01-9 13:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
319
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site s…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13213
|
2025-01-9 13:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
320
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13212
|
2025-01-9 13:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|