281
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-10 16:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
282
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modifica…
|
CWE-862
Missing Authorization
|
CVE-2024-12606
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
283
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the…
|
CWE-89
SQL Injection
|
CVE-2024-12473
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
284
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
|
CWE-284
Improper Access Control
|
CVE-2025-21380
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
285
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a u…
|
-
|
CVE-2024-56377
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
286
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the re…
|
-
|
CVE-2024-56376
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
287
|
8.8 |
HIGH
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-21385
|
2025-01-10 07:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
288
|
- |
|
-
|
-
|
In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An atta…
|
-
|
CVE-2024-55553
|
2025-01-10 07:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
289
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
quota: flush quota_release_work upon quota writeback
One of the paths quota writeback is called from is:
freeze_super()
sync_f…
|
NVD-CWE-noinfo
|
CVE-2024-56780
|
2025-01-10 06:50 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
290
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check
The return value of drm_atomic_get_crtc_state() …
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-56778
|
2025-01-10 06:50 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|