761
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument username leads…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0721
|
2025-01-27 09:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
762
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rt…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2025-0720
|
2025-01-27 08:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
763
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
|
CWE-863
Incorrect Authorization
|
CVE-2023-50946
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
764
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2023-50945
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
765
|
4.2 |
MEDIUM
Physics
|
-
|
-
|
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
|
CWE-295
Improper Certificate Validation
|
CVE-2023-38009
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
766
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2024-31906
|
2025-01-27 00:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
767
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insuff…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13505
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
768
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12334
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
769
|
8.8 |
HIGH
Network
|
-
|
-
|
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_option…
|
CWE-862
Missing Authorization
|
CVE-2024-11936
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
770
|
8.8 |
HIGH
Network
|
-
|
-
|
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce valid…
|
CWE-352
Origin Validation Error
|
CVE-2024-11641
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|