1041
|
- |
|
-
|
-
|
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-23184
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1042
|
- |
|
-
|
-
|
NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.
|
-
|
CVE-2024-6466
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1043
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization a…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13404
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1044
|
5.3 |
MEDIUM
Network
-
|
-
|
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and w…
|
CWE-862
Missing Authorization
|
CVE-2024-12104
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1045
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_optio…
|
CWE-352
Origin Validation Error
|
CVE-2024-12005
|
2025-01-21 19:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1046
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output e…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0371
|
2025-01-21 18:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1047
|
8.8 |
HIGH
Network
|
-
|
-
|
The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace'…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10936
|
2025-01-21 18:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1048
|
5.3 |
MEDIUM
Network
-
|
-
|
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly acce…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-13536
|
2025-01-21 14:15 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1049
|
- |
|
-
|
-
|
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.
|
-
|
CVE-2025-0356
|
2025-01-21 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1050
|
- |
|
-
|
-
|
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.…
|
-
|
CVE-2025-0355
|
2025-01-21 13:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|