1101
|
7.5 |
HIGH
Network
-
|
-
|
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (…
|
CWE-789 CWE-476
Memory Allocation with Excessive Size Value NULL Pointer Dereference
|
CVE-2025-20165
|
2025-01-23 02:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1102
|
5.3 |
MEDIUM
Network
-
|
-
|
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected d…
|
CWE-122 CWE-120
Heap-based Buffer Overflow Classic Buffer Overflow
|
CVE-2025-20128
|
2025-01-23 02:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1103
|
4.3 |
MEDIUM
Network
|
07fly
|
07flycms
|
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
|
CWE-352
Origin Validation Error
|
CVE-2024-57161
|
2025-01-23 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1104
|
4.3 |
MEDIUM
Network
|
07fly
|
07flycms
|
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
|
CWE-352
Origin Validation Error
|
CVE-2024-57160
|
2025-01-23 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1105
|
8.8 |
HIGH
Network
|
jfinaloa_project
|
jfinaloa
|
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
|
CWE-89
SQL Injection
|
CVE-2024-57775
|
2025-01-23 02:07 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1106
|
9.8 |
CRITICAL
Network
tenda
|
ac18_firmware
|
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
|
CWE-77
Command Injection
|
CVE-2024-57583
|
2025-01-23 01:53 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1107
|
9.8 |
CRITICAL
Network
tenda
|
ac18_firmware
|
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-57575
|
2025-01-23 01:53 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1108
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate p…
|
NVD-CWE-noinfo
|
CVE-2024-57726
|
2025-01-23 01:25 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1109
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leetoo Toocheke Companion allows Stored XSS. This issue affects Toocheke Companion: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23992
|
2025-01-23 01:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1110
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NotFound Muzaara Google Ads Report allows Object Injection. This issue affects Muzaara Google Ads Report: from n/a through 3.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-23914
|
2025-01-23 01:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|