1031
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER allows Cross Site Request Forgery.This issue affects W3SPEEDSTER: from n/a through 7.33.
|
CWE-352
Origin Validation Error
|
CVE-2025-23765
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1032
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Copy Move Posts: from n/a through 1.6.
|
CWE-862
Missing Authorization
|
CVE-2025-23764
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1033
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woo Tuner: from n/a through 0.1.2.
|
CWE-862
Missing Authorization
|
CVE-2025-23761
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1034
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Volkov Chatter allows Stored XSS. This issue affects Chatter: from n/a through 1.0.1.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23760
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1035
|
- |
|
-
|
-
|
An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
|
-
|
CVE-2024-57618
|
2025-01-17 06:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1036
|
6.2 |
MEDIUM
Local
|
freetype
|
freetype
|
FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2025-23022
|
2025-01-17 06:12 |
2025-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1037
|
5.4 |
MEDIUM
Network
|
vanderbilt
|
redcap
|
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-56377
|
2025-01-17 06:10 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1038
|
5.4 |
MEDIUM
Network
|
vanderbilt
|
redcap
|
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the re…
|
CWE-79
Cross-site Scripting
|
CVE-2024-56376
|
2025-01-17 06:10 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1039
|
9.8 |
CRITICAL
Network
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
|
CWE-22
Path Traversal
|
CVE-2024-13181
|
2025-01-17 06:02 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1040
|
7.5 |
HIGH
Network
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
|
CWE-22
Path Traversal
|
CVE-2024-13180
|
2025-01-17 06:01 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|