Latest CVE Feed
-
6.5
MEDIUMCVE-2025-20072
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
4.6
MEDIUMCVE-2024-57776
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57775
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-57774
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
-
4.8
MEDIUMCVE-2024-57773
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57772
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-57771
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-57770
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-57769
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57768
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.... Read more
Affected Products : jfinaloa- Published: Jan. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
0.0
NONECVE-2024-50633
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentiona... Read more
Affected Products : indico- Published: Jan. 16, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-41746
IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d... Read more
- Published: Jan. 16, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
2.6
LOWCVE-2024-37181
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Race Condition
-
5.3
MEDIUMCVE-2025-0518
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C . This issue a... Read more
Affected Products : ffmpeg- Published: Jan. 16, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Memory Corruption
-
3.5
LOWCVE-2024-57611
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.2
HIGHCVE-2024-57162
Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.... Read more
Affected Products : cybercafe_management_system- Published: Jan. 16, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-57161
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-57160
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2024-57159
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.... Read more
Affected Products : 07flycms- Published: Jan. 16, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-0473
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoi... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration