1571
|
- |
|
-
|
-
|
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.
|
-
|
CVE-2024-50690
|
2025-01-25 08:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1572
|
- |
|
-
|
-
|
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaSc…
|
-
|
CVE-2024-57329
|
2025-01-25 07:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1573
|
- |
|
-
|
-
|
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code i…
|
-
|
CVE-2024-57326
|
2025-01-25 07:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1574
|
- |
|
-
|
-
|
A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProgramData\iTop VPN\Downloader\vpn6.
|
-
|
CVE-2024-53588
|
2025-01-25 07:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1575
|
6.1 |
MEDIUM
Network
|
icopydoc
|
xml_for_google_merchant_center
|
The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id' parameter in all versions up to, and including, 3.0.11 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13406
|
2025-01-25 06:20 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1576
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0710
|
2025-01-25 06:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1577
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipul…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0709
|
2025-01-25 06:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1578
|
- |
|
-
|
-
|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does …
|
-
|
CVE-2025-24025
|
2025-01-25 06:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1579
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component
|
-
|
CVE-2024-57556
|
2025-01-25 06:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1580
|
6.1 |
MEDIUM
Network
|
themify
|
themify_builder
|
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-13319
|
2025-01-25 06:06 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|