1021
|
- |
|
-
|
-
|
An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_tools/mpegts.c:2163 that can cause a denial of service (DOS…
|
-
|
CVE-2024-57184
|
2025-01-25 00:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1022
|
- |
|
-
|
-
|
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns
|
-
|
CVE-2022-47090
|
2025-01-25 00:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1023
|
- |
|
-
|
-
|
Information Disclosure in API in Replicated Replicated Classic versions prior to 2.53.1 on all platforms allows authenticated users with Admin Console access to retrieve sensitive data, including app…
|
-
|
CVE-2021-42718
|
2025-01-25 00:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1024
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-41739
|
2025-01-24 23:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1025
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. Thi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-11913
|
2025-01-24 23:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1026
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas…
|
CWE-1230
Exposure of Sensitive Information Through Metadata
|
CVE-2024-10324
|
2025-01-24 23:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1027
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FooGallery Captions allows Reflected XSS. This issue affects FooGallery Captions: from n…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23889
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1028
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Custom Page Extensions allows Reflected XSS. This issue affects Custom Page Extensions: …
|
CWE-79
Cross-site Scripting
|
CVE-2025-23888
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1029
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MJ Contact us allows Reflected XSS. This issue affects MJ Contact us: from n/a through 5…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23885
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1030
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Sticky Button allows Stored XSS. This issue affects Sticky Button: from n/a through 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23839
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|