1961
|
- |
|
-
|
-
|
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious …
|
CWE-22
Path Traversal
|
CVE-2025-22130
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1962
|
4.8 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics infor…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-20126
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1963
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks agains…
|
CWE-79
Cross-site Scripting
|
CVE-2025-20123
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1964
|
- |
|
-
|
-
|
RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-55656
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1965
|
- |
|
-
|
-
|
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL q…
|
-
|
CVE-2024-55517
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1966
|
- |
|
-
|
-
|
RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT…
|
CWE-190 CWE-122
Integer Overflow or Wraparound Heap-based Buffer Overflow
|
CVE-2024-51737
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1967
|
- |
|
-
|
-
|
RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially c…
|
CWE-190 CWE-122
Integer Overflow or Wraparound Heap-based Buffer Overflow
|
CVE-2024-51480
|
2025-01-9 01:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1968
|
- |
|
-
|
-
|
The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against…
|
-
|
CVE-2024-12585
|
2025-01-9 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1969
|
- |
|
-
|
-
|
The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow us…
|
-
|
CVE-2024-10151
|
2025-01-9 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1970
|
- |
|
-
|
-
|
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
|
-
|
CVE-2022-45186
|
2025-01-9 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|