1001
|
5.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uyumsoft Informatin Systems Uyumsoft ERP allows XSS Using Invalid Characters, Reflected XS…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10539
|
2025-01-23 23:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1002
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_set_pipapo: fix initial map fill
The initial buffer has to be inited to all-ones, but it must restrict
it to the si…
|
-
|
CVE-2024-57947
|
2025-01-23 23:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1003
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 d…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13422
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1004
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Cliptakes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cliptakes_input_email' shortcode in all versions up to, and including, 1.3.4 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13389
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1005
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdf_results_by_ajax' shortcode in all versions up to, and including, 1.3…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13340
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1006
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient escaping on the user supplied para…
|
CWE-89
SQL Injection
|
CVE-2024-13236
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1007
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12504
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1008
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12118
|
2025-01-23 21:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1009
|
- |
|
-
|
-
|
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 allows a highly privileged attacker to cause denial of service via configuration change.
|
-
|
CVE-2025-0648
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1010
|
- |
|
-
|
-
|
Denial of service condition in M-Files Server in versions before
25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
|
-
|
CVE-2025-0635
|
2025-01-23 20:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|