2261
|
- |
|
-
|
-
|
The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w…
|
-
|
CVE-2024-11849
|
2025-01-6 23:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2262
|
- |
|
-
|
-
|
The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting att…
|
-
|
CVE-2024-11356
|
2025-01-6 23:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2263
|
3.9 |
LOW
Physics
|
-
|
-
|
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus …
|
CWE-78
OS Command
|
CVE-2024-12970
|
2025-01-6 21:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2264
|
- |
|
-
|
-
|
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uplo…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13145
|
2025-01-6 10:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2265
|
- |
|
-
|
-
|
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogCont…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13144
|
2025-01-6 09:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2266
|
- |
|
-
|
-
|
A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/system/controller/Per…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-13143
|
2025-01-6 09:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2267
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html.…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2025-0227
|
2025-01-6 03:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2268
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /co…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2025-0226
|
2025-01-6 03:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2269
|
- |
|
-
|
-
|
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/…
|
CWE-23 CWE-25
Relative Path Traversal
|
CVE-2025-0225
|
2025-01-6 02:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2270
|
- |
|
-
|
-
|
A vulnerability was found in Provision-ISR SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH-16200A-2(1U), SH-16200A-5(1U) and NVR5-8200PX up to 20241220. It has been declared as problematic. Affected…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2025-0224
|
2025-01-6 02:15 |
2025-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|