751
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11870
|
2025-01-15 17:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
752
|
- |
|
-
|
-
|
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison betwe…
|
-
|
CVE-2024-12085
|
2025-01-15 16:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
753
|
- |
|
-
|
-
|
Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file which is specially crafted by an attacker, arbitrary code may be executed. As a r…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-55577
|
2025-01-15 15:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
754
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortcode in all versions up to, and including, 1.4.15 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13394
|
2025-01-15 15:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
755
|
- |
|
-
|
-
|
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
|
-
|
CVE-2025-23061
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
756
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-22394
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
757
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability.
A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary…
|
CWE-362
Race Condition
|
CVE-2025-21101
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
758
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13334
|
2025-01-15 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
759
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
|
CWE-416
Use After Free
|
CVE-2025-21335
|
2025-01-15 11:00 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
760
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
|
CWE-416
Use After Free
|
CVE-2025-21334
|
2025-01-15 11:00 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|