Latest CVE Feed
-
5.3
MEDIUMCVE-2025-22376
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Cryptography
-
9.0
HIGHCVE-2024-13129
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads to os command i... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-0198
A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id lead... Read more
Affected Products : point_of_sales_and_inventory_management_system- Published: Jan. 03, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-56332
Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that... Read more
Affected Products : next.js- Published: Jan. 03, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-0197
A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The a... Read more
Affected Products : point_of_sales_and_inventory_management_system- Published: Jan. 03, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-0196
A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possibl... Read more
Affected Products : point_of_sales_and_inventory_management_system- Published: Jan. 03, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-0195
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads... Read more
Affected Products : point_of_sales_and_inventory_management_system- Published: Jan. 03, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-56412
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker c... Read more
- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56411
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed without san... Read more
- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-56410
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom propertie... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-36613
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.... Read more
Affected Products : ffmpeg- Published: Jan. 03, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-35365
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.... Read more
Affected Products : ffmpeg- Published: Jan. 03, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-21610
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javasc... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-21609
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a ... Read more
Affected Products : siyuan- Published: Jan. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2024-56514
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or a... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2024-56513
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive p... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Authorization
-
8.3
HIGHCVE-2024-56409
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsh... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56366
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspread... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56365
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/php... Read more
- Published: Jan. 03, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2024-56408
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` file, which leads to the pos... Read more
- Published: Jan. 03, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting