1481
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22597
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1482
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22596
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1483
|
- |
|
-
|
-
|
Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execut…
|
CWE-22 CWE-94 CWE-434
Path Traversal Code Injection Unrestricted Upload of File with Dangerous Type
|
CVE-2025-22152
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1484
|
- |
|
-
|
-
|
DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause t…
|
CWE-289
Authentication Bypass by Alternate Name
|
CVE-2024-56511
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1485
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2024-46210
|
2025-01-11 01:15 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1486
|
- |
|
-
|
-
|
An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" G…
|
-
|
CVE-2024-57687
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1487
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.
|
-
|
CVE-2024-51229
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1488
|
- |
|
-
|
-
|
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQ…
|
-
|
CVE-2024-54762
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1489
|
- |
|
-
|
-
|
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
|
-
|
CVE-2024-54761
|
2025-01-11 01:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1490
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ar8035_firmware c-v2x_9150_firmware csrb31024_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware msm8996au_firmware qam8295p_firmware qca63…
|
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-33067
|
2025-01-11 00:39 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|