5.3

CVSS4.0

CVE-2024-13191 - ZeroWdd myblog uploadController.java upload unrestricted upload

A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack may be init…

πŸ“… Published: Jan. 8, 2025, 10:31 p.m. πŸ”„ Last Modified: May 28, 2025, 8:11 p.m.

0.0

CVE-2025-0351 -

Voluntarily withdrawn

πŸ“… Published: Jan. 8, 2025, 10:16 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 9:35 a.m.

7

CVSS3.1

CVE-2025-0283 -

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

πŸ“… Published: Jan. 8, 2025, 10:15 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

9

CVSS3.1

CVE-2025-0282 -

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

πŸ“… Published: Jan. 8, 2025, 10:15 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 1:54 p.m.

5.3

CVSS4.0

CVE-2024-13190 - ZeroWdd myblog BlogMapper.xml xml injection

A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit…

πŸ“… Published: Jan. 8, 2025, 9 p.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

1.9

CVSS4.0

CVE-2024-53995 - GHSL-2024-288: SickChill open redirect in login

SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to o…

πŸ“… Published: Jan. 8, 2025, 8:44 p.m. πŸ”„ Last Modified: Feb. 12, 2025, 8:31 p.m.

3.4

CVSS3.1

CVE-2024-54010 - Unauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 seri…

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configurat…

πŸ“… Published: Jan. 8, 2025, 8:42 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 6:15 p.m.

6.3

CVSS4.0

CVE-2025-22145 - Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at …

πŸ“… Published: Jan. 8, 2025, 8:40 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 1:15 p.m.

4.3

CVSS3.1

CVE-2024-12431 - Missing Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

πŸ“… Published: Jan. 8, 2025, 8:30 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-0194 - Insertion of Sensitive Information into Externally-Accessible File or Directory in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.

πŸ“… Published: Jan. 8, 2025, 8:02 p.m. πŸ”„ Last Modified: July 11, 2025, 8:34 p.m.
Total resulsts: 343747
Page 6678 of 34,375
Β« previous page Β» next page
Filters