651
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Infomaniak Staff VOD Infomaniak allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VOD Infomaniak: from n/a through 1.5.…
|
CWE-862
Missing Authorization
|
CVE-2025-22729
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
652
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MojofyWP Product Carousel For WooCommerce – WoorouSell allows Stored XSS.This issue affects Produ…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22724
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
653
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NCiphers SEO Bulk Editor allows Stored XSS.This issue affects SEO Bulk Editor: from n/a through 1…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22587
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
654
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affects Course Migration for LearnDash: from 1.0.2 throu…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-22346
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
655
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AGILELOGIX Free Google Maps allows Stored XSS.This issue affects Free Google Maps: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22329
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
656
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in galleryape Photo Gallery – Image Gallery by Ape allows Reflected XSS.This issue affects Photo Gal…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22317
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
657
|
- |
|
-
|
-
|
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which …
|
-
|
CVE-2025-21088
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
658
|
- |
|
-
|
-
|
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by u…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-8603
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
659
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 5.5.6.
|
CWE-862
Missing Authorization
|
CVE-2024-56295
|
2025-01-16 01:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
660
|
- |
|
-
|
-
|
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data.
This issue briefly impa…
|
-
|
CVE-2025-23073
|
2025-01-16 01:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|