331
|
- |
|
-
|
-
|
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.
|
-
|
CVE-2024-56113
|
2025-01-10 20:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
332
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sani…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13183
|
2025-01-10 17:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
333
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0311
|
2025-01-10 16:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
334
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modifica…
|
CWE-862
Missing Authorization
|
CVE-2024-12606
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
335
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the…
|
CWE-89
SQL Injection
|
CVE-2024-12473
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
336
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
|
CWE-284
Improper Access Control
|
CVE-2025-21380
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
337
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a u…
|
-
|
CVE-2024-56377
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
338
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the re…
|
-
|
CVE-2024-56376
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
339
|
8.8 |
HIGH
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-21385
|
2025-01-10 07:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
340
|
- |
|
-
|
-
|
In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An atta…
|
-
|
CVE-2024-55553
|
2025-01-10 07:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|