-
CVE-2025-23125 – “Apache Struts Cross-Site Request Forgery Vulnerability”
CVE ID : CVE-2025-23125 Published : Jan. 11, 2025, 3:15 p.m. | 1 day ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source
-
CVE-2025-23124 – CVE-2022-4792: Dell EMC NetWorker Authentication Bypass Vulnerability
CVE ID : CVE-2025-23124 Published : Jan. 11, 2025, 3:15 p.m. | 1 day ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source
-
CVE-2024-57880 – Intel ASoC SOF SDW Array Index Out-of-Bounds Vulnerability
CVE ID : CVE-2024-57880 Published : Jan. 11, 2025, 3:15 p.m. | 1 day ago Description : In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array The code uses the initialised member of the asoc_sdw_dailink struct to determine if a member of the array…
-
CVE-2024-57879 – Qualcomm Bluetooth Linux Module – Resource Leaking Vulnerability
CVE ID : CVE-2024-57879 Published : Jan. 11, 2025, 3:15 p.m. | 1 day ago Description : In the Linux kernel, the following vulnerability has been resolved: Bluetooth: iso: Always release hdev at the end of iso_listen_bis Since hci_get_route holds the device before returning, the hdev should be released with hci_dev_put at the end of iso_listen_bis…
-
CVE-2024-57878 – Linux Kernel Arm64 Ptrace FPMR Initialization Leak
CVE ID : CVE-2024-57878 Published : Jan. 11, 2025, 3:15 p.m. | 1 day ago Description : In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR Currently fpmr_set() doesn’t initialize the temporary ‘fpmr’ variable, and a SETREGSET call with a length of zero will leave this uninitialized. Consequently…
-
CVE-2024-12877 – GiveWP – Donation Plugin and Fundraising Platform PHP Object Injection and Remote Code Execution
CVE ID : CVE-2024-12877 Published : Jan. 11, 2025, 8:15 a.m. | 1 day, 7 hours ago Description : The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like ‘firstName’. This makes…
-
CVE-2024-9188 – Oracle WebLogic SQL Injection Vulnerability
CVE ID : CVE-2024-9188 Published : Jan. 10, 2025, 10:15 p.m. | 1 day, 17 hours ago Description : Specially constructed queries cause cross platform scripting leaking administrator tokens Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source
-
CVE-2024-42168 – HCL MyXalytics HTTP Request Hijacking Vulnerability
CVE ID : CVE-2024-42168 Published : Jan. 11, 2025, 3:15 a.m. | 1 day, 12 hours ago Description : HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the application to retrieve and process that content. Severity: 8.9 | HIGH Visit the…
-
CVE-2024-9134 – Apache Reporting SQL Injection Privilege Escalation Vulnerability
CVE ID : CVE-2024-9134 Published : Jan. 10, 2025, 10:15 p.m. | 1 day, 17 hours ago Description : Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. Severity: 8.3 |…
-
CVE-2024-9132 – “FortiOS Path Traversal”
CVE ID : CVE-2024-9132 Published : Jan. 10, 2025, 10:15 p.m. | 1 day, 17 hours ago Description : The administrator is able to configure an insecure captive portal script Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go to Source