461
|
- |
|
-
|
-
|
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-0303
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
462
|
- |
|
-
|
-
|
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2025-0302
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
463
|
- |
|
-
|
-
|
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product …
|
-
|
CVE-2025-1077
|
2025-02-7 18:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
464
|
- |
|
-
|
-
|
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malici…
|
-
|
CVE-2025-22880
|
2025-02-7 17:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
465
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via the 'bse-ele…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13841
|
2025-02-7 16:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
466
|
- |
|
-
|
-
|
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service co…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-1072
|
2025-02-7 13:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
467
|
- |
|
-
|
-
|
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with r…
|
CWE-80
Basic XSS
|
CVE-2025-22402
|
2025-02-7 12:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
468
|
5.3 |
MEDIUM
Network
-
|
-
|
A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. The manipulation leads to path t…
|
CWE-23 CWE-24
Relative Path Traversal Path Traversal: '../filedir'
|
CVE-2025-1086
|
2025-02-7 11:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
469
|
9.8 |
CRITICAL
Network
-
|
-
|
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied …
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-1061
|
2025-02-7 11:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
470
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability, which was classified as problematic, was found in Animati PACS up to 1.24.12.09.03. This affects an unknown part of the file /login. The manipulation of the argument p leads to cross…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-1085
|
2025-02-7 10:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|