1641
|
5.3 |
MEDIUM
Network
-
|
-
|
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected d…
|
CWE-122 CWE-120
Heap-based Buffer Overflow Classic Buffer Overflow
|
CVE-2025-20128
|
2025-01-23 02:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1642
|
4.4 |
MEDIUM
Network
|
-
|
-
|
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51457
|
2025-01-23 02:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1643
|
- |
|
-
|
-
|
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. Th…
|
-
|
CVE-2024-49734
|
2025-01-23 02:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1644
|
4.3 |
MEDIUM
Network
|
07fly
|
07flycms
|
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
|
CWE-352
Origin Validation Error
|
CVE-2024-57161
|
2025-01-23 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1645
|
4.3 |
MEDIUM
Network
|
07fly
|
07flycms
|
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
|
CWE-352
Origin Validation Error
|
CVE-2024-57160
|
2025-01-23 02:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1646
|
8.8 |
HIGH
Network
|
jfinaloa_project
|
jfinaloa
|
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
|
CWE-89
SQL Injection
|
CVE-2024-57775
|
2025-01-23 02:07 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1647
|
9.8 |
CRITICAL
Network
tenda
|
ac18_firmware
|
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
|
CWE-77
Command Injection
|
CVE-2024-57583
|
2025-01-23 01:53 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1648
|
9.8 |
CRITICAL
Network
tenda
|
ac18_firmware
|
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-57575
|
2025-01-23 01:53 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1649
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate p…
|
NVD-CWE-noinfo
|
CVE-2024-57726
|
2025-01-23 01:25 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1650
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leetoo Toocheke Companion allows Stored XSS. This issue affects Toocheke Companion: from n/a thro…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23992
|
2025-01-23 01:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|