641
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortcode in all versions up to, and including, 1.4.15 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13394
|
2025-01-15 15:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
642
|
- |
|
-
|
-
|
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
|
-
|
CVE-2025-23061
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
643
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-22394
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
644
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability.
A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary…
|
CWE-362
Race Condition
|
CVE-2025-21101
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
645
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13334
|
2025-01-15 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
646
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
|
CWE-416
Use After Free
|
CVE-2025-21335
|
2025-01-15 11:00 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
647
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
|
CWE-416
Use After Free
|
CVE-2025-21334
|
2025-01-15 11:00 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
648
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2025-21333
|
2025-01-15 11:00 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
649
|
- |
|
-
|
-
|
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2024-55591
|
2025-01-15 11:00 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
650
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payl…
|
-
|
CVE-2025-22997
|
2025-01-15 09:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|