31
|
- |
|
-
|
-
|
A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality…
Update
|
-
|
CVE-2024-13130
|
2025-01-10 23:15 |
2025-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
32
|
- |
|
-
|
-
|
A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/create_product.php of the com…
New
|
-
|
CVE-2024-13205
|
2025-01-10 22:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
33
|
- |
|
-
|
-
|
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadPara…
New
|
-
|
CVE-2025-23016
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
34
|
5.3 |
MEDIUM
Network
-
|
-
|
The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including,…
New
|
CWE-463
|
CVE-2024-13318
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
35
|
- |
|
-
|
-
|
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.
New
|
-
|
CVE-2024-56113
|
2025-01-10 20:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
36
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sani…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13183
|
2025-01-10 17:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
37
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-10 16:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
38
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modifica…
New
|
CWE-862
Missing Authorization
|
CVE-2024-12606
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
39
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the…
New
|
CWE-89
SQL Injection
|
CVE-2024-12473
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
40
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
New
|
CWE-284
Improper Access Control
|
CVE-2025-21380
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|