101
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in thunderbax WP Admin Custom Page allows Stored XSS. This issue affects WP Admin Custom Page: from n/a through 1.5.0.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-25072
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
102
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in topplugins Vignette Ads allows Stored XSS. This issue affects Vignette Ads: from n/a through 0.2.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-25071
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
103
|
- |
|
-
|
-
|
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
New
|
CWE-416
Use After Free
|
CVE-2025-0304
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
104
|
- |
|
-
|
-
|
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-0303
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
105
|
- |
|
-
|
-
|
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2025-0302
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
106
|
- |
|
-
|
-
|
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product …
New
|
-
|
CVE-2025-1077
|
2025-02-7 18:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
107
|
- |
|
-
|
-
|
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malici…
New
|
-
|
CVE-2025-22880
|
2025-02-7 17:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
108
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via the 'bse-ele…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13841
|
2025-02-7 16:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
109
|
- |
|
-
|
-
|
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service co…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-1072
|
2025-02-7 13:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
110
|
- |
|
-
|
-
|
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with r…
New
|
CWE-80
Basic XSS
|
CVE-2025-22402
|
2025-02-7 12:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|