5.4

CVSS3.1

CVE-2025-23221 - Fedify has an Infinite loop and Blind SSRF found inside the Webfinger mechanism

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulnerability allows a user to maneuver the Webfinger mechanism to perform a GET request to any internal resource on any Host, Port, URL combination regardless of present security mech…

πŸ“… Published: Jan. 20, 2025, 4:49 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-24013 - CodeIgniter validation of header name and value

CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct deliberately malformed headers with Header class. This could disrupt application functionality, potentially causing errors or gener…

πŸ“… Published: Jan. 20, 2025, 3:57 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 7:17 p.m.

6.5

CVSS3.1

CVE-2025-24010 - Vite allows any websites to send any requests to the development server and read the response

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4…

πŸ“… Published: Jan. 20, 2025, 3:53 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 6:35 p.m.

10

CVSS4.0

CVE-2025-23220 - WeGIA has a SQL Injection endpoint 'adicionar_raca.php' parameter 'raca'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_raca.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in t…

πŸ“… Published: Jan. 20, 2025, 3:48 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2025-23219 - WeGIA has a SQL Injection endpoint 'adicionar_cor.php' parameter 'cor'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_cor.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in th…

πŸ“… Published: Jan. 20, 2025, 3:47 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

10

CVSS4.0

CVE-2025-23218 - WeGIA has a SQL Injection endpoint 'adicionar_especie.php' parameter 'especie'

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_especie.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands i…

πŸ“… Published: Jan. 20, 2025, 3:45 p.m. πŸ”„ Last Modified: Feb. 28, 2025, 7:18 p.m.

6.8

CVSS3.1

CVE-2025-23044 - Cross-Site Request Forgery (CSRF) allows creating admin account with POST request

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit 14acb704891245bf17…

πŸ“… Published: Jan. 20, 2025, 3:43 p.m. πŸ”„ Last Modified: May 7, 2025, 6:59 p.m.

5

CVSS3.1

CVE-2025-22620 - gix-worktree-state nonexclusive checkout sets executable files world-writable

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This …

πŸ“… Published: Jan. 20, 2025, 3:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-22131 - Cross-Site Scripting (XSS) vulnerability in generateNavigation() function

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Cross-Site Scripting (XSS) vulnerability in the code which translates the XLSX file into a HTML representation and displays it in the response.

πŸ“… Published: Jan. 20, 2025, 3:31 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

7.7

CVSS4.0

CVE-2024-51738 - Sunshine improperly enforces pairing protocol request order

Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking a legitimate pairing…

πŸ“… Published: Jan. 20, 2025, 3:26 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 9:33 p.m.
Total resulsts: 349182
Page 7042 of 34,919
Β« previous page Β» next page
Filters