Medium - CVE-2024-49349 - IBM Financial Transaction Manager for SWIFT...
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed...
NA - CVE-2024-57432 - macrozheng mall-tiny 1.0.1 suffers from...
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used...
NA - CVE-2025-23001 - A Host Header Injection vulnerability exists in...
A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP...
NA - CVE-2025-0938 - The Python standard library functions...
The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are...
NA - CVE-2025-24891 - Dumb Drop is a file upload application. Users...
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs...
Medium - CVE-2025-0844 - A vulnerability was found in needyamin Library...
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file signup.php of the...
High - CVE-2025-0846 - A vulnerability was found in 1000 Projects...
A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/AdminLogin.php. The manipulation...
High - CVE-2025-0847 - A vulnerability was found in 1000 Projects...
A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component...