891
|
- |
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in ThimPress FundPress allows Object Injection. This issue affects FundPress: from n/a through 2.0.6.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-24601
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
892
|
- |
|
-
|
-
|
Missing Authorization vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Store Kit Elem…
|
CWE-862
Missing Authorization
|
CVE-2025-24584
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
893
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3…
|
CWE-352
Origin Validation Error
|
CVE-2025-24533
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
894
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint allows Reflected XSS. This iss…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23792
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
895
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clodeo Shipdeo allows Reflected XSS. This issue affects Shipdeo: from n/a through 1.2.8.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23457
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
896
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple Locator allows Reflected XSS. This issue affects Simple Locator: from n/a through…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22513
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
897
|
- |
|
-
|
-
|
Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET request parameter sent to a specific endpoint.
The vulnerability has been fixed by …
|
-
|
CVE-2024-11348
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
898
|
8.9 |
HIGH
Network
|
-
|
-
|
A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table view in the portal, for example, on any of the /main/configmanagement/* endpoints, the front-end gener…
|
CWE-79
Cross-site Scripting
|
CVE-2022-4975
|
2025-01-27 23:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
899
|
- |
|
-
|
-
|
A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON a…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-0696
|
2025-01-27 20:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
900
|
- |
|
-
|
-
|
An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-0695
|
2025-01-27 20:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|