1711
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipu…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2025-0870
|
2025-01-30 22:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1712
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0869
|
2025-01-30 22:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1713
|
- |
|
-
|
-
|
A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0746
|
2025-01-30 21:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1714
|
- |
|
-
|
-
|
An Improper Access Control vulnerability has been found in EmbedAI
2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing th…
|
CWE-284
Improper Access Control
|
CVE-2025-0740
|
2025-01-30 20:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1715
|
- |
|
-
|
-
|
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by changing th…
|
CWE-284
Improper Access Control
|
CVE-2025-0739
|
2025-01-30 20:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1716
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, 1.9 due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12524
|
2025-01-30 20:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1717
|
- |
|
-
|
-
|
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could po…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2025-21107
|
2025-01-30 19:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1718
|
- |
|
-
|
-
|
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Won…
|
CWE-269
Improper Privilege Management
|
CVE-2025-0834
|
2025-01-30 18:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1719
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12921
|
2025-01-30 15:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1720
|
- |
|
-
|
-
|
The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contri…
|
-
|
CVE-2024-10309
|
2025-01-30 15:15 |
2025-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|