1921
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird <…
|
CWE-416
Use After Free
|
CVE-2025-1012
|
2025-02-7 04:33 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1922
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefo…
|
NVD-CWE-noinfo
|
CVE-2025-1011
|
2025-02-7 04:31 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1923
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < …
|
CWE-416
Use After Free
|
CVE-2025-1010
|
2025-02-7 04:30 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1924
|
9.8 |
CRITICAL
Network
mozilla
|
firefox thunderbird
|
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, …
|
CWE-416
Use After Free
|
CVE-2025-1009
|
2025-02-7 04:28 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1925
|
- |
|
-
|
-
|
Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log.
|
-
|
CVE-2024-13416
|
2025-02-7 04:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1926
|
- |
|
-
|
-
|
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been prev…
|
-
|
CVE-2024-43779
|
2025-02-7 04:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1927
|
- |
|
-
|
-
|
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An…
|
-
|
CVE-2024-39272
|
2025-02-7 04:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1928
|
- |
|
-
|
-
|
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24981
|
2025-02-7 03:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1929
|
- |
|
-
|
-
|
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.1 and below, a malic…
|
CWE-441 CWE-288
Confused Deputy Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-23217
|
2025-02-7 03:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1930
|
- |
|
-
|
-
|
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
|
-
|
CVE-2025-25181
|
2025-02-7 03:15 |
2025-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|