CVE-2025-0196 – Exploitable SQL Injection Vulnerability in Code-Projects Point of Sales and Inventory Management System

The following table lists the changes that have been made to the CVE-2025-0196 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2025-0195 – Code-Projects Point of Sales and Inventory Management System SQL Injection

The following table lists the changes that have been made to the CVE-2025-0195 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2024-56412 – PhpSpreadsheet Cross-Site Scripting (XSS) Bypass Vulnerability

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the library processes the javascript protocol with special characters and generates an […]

CVE-2024-56411 – PhpSpreadsheet XSS in Hyperlink Base

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed without sanitizing the hyperlink base. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the […]

CVE-2024-56410 – “PhpSpreadsheet Custom Properties XSS”

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom properties. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 contain a patch for the issue.

CVE-2024-36613 – FFmpeg DXA Demuxer Integer Overflow Vulnerability

The following table lists the changes that have been made to the CVE-2024-36613 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2024-35365 – FFmpeg Double-Free Vulnerability

The following table lists the changes that have been made to the CVE-2024-35365 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2025-21610 – Trix Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-21610 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2025-21609 – SiYuan Note File Deletion Vulnerability

The following table lists the changes that have been made to the CVE-2025-21609 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Jan. 03, 2025 Action […]

CVE-2024-56514 – Karmada TarSlip Vulnerability Allows File System Tampering

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs) needed by Karmada. The CRDs are downloaded as a […]