891
|
- |
|
-
|
-
|
Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
|
CWE-420
Unprotected Alternate Channel
|
CVE-2022-28693
|
2025-02-15 06:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
892
|
- |
|
-
|
-
|
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via loca…
|
CWE-1204
|
CVE-2022-26083
|
2025-02-15 06:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
893
|
- |
|
-
|
-
|
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attac…
|
-
|
CVE-2024-37600
|
2025-02-15 06:15 |
2025-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
894
|
- |
|
-
|
-
|
Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information
|
-
|
CVE-2024-57777
|
2025-02-15 06:15 |
2025-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
895
|
- |
|
-
|
-
|
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to version 5.26.0 of vega and 5.4.2 of vega-selections, the `vlSelecti…
|
CWE-79
Cross-site Scripting
|
CVE-2025-25304
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
896
|
- |
|
-
|
-
|
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint c…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-25297
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
897
|
- |
|
-
|
-
|
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appro…
|
CWE-79
Cross-site Scripting
|
CVE-2025-25296
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
898
|
- |
|
-
|
-
|
@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the p…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2025-25289
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
899
|
- |
|
-
|
-
|
@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, whe…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2025-25288
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
900
|
- |
|
-
|
-
|
@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2025-25285
|
2025-02-15 05:15 |
2025-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|