271
|
- |
|
-
|
-
|
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadPara…
New
|
-
|
CVE-2025-23016
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
272
|
5.3 |
MEDIUM
Network
-
|
-
|
The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including,…
New
|
CWE-463
|
CVE-2024-13318
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
273
|
- |
|
-
|
-
|
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.
New
|
-
|
CVE-2024-56113
|
2025-01-10 20:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
274
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13183
|
2025-01-10 17:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-10 16:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
276
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modifica…
New
|
CWE-862
Missing Authorization
|
CVE-2024-12606
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
277
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the…
New
|
CWE-89
SQL Injection
|
CVE-2024-12473
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
278
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
New
|
CWE-284
Improper Access Control
|
CVE-2025-21380
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
279
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a u…
New
|
-
|
CVE-2024-56377
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
280
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the re…
New
|
-
|
CVE-2024-56376
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|