571
|
3.9 |
LOW
Physics
|
google
|
android
|
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor ha…
|
CWE-125
Out-of-bounds Read
|
CVE-2025-20643
|
2025-02-5 00:19 |
2025-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
572
|
- |
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0…
|
CWE-94
Code Injection
|
CVE-2025-24677
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
573
|
- |
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.1.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-24648
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
574
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check allows Reflected XSS. This issue affects WP24 Domain Check: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24602
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
575
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24599
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
576
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24598
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
577
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs allows Reflected XSS. This issue affects Find Content IDs: fr…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23645
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
578
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Landoweb Programador World Cup Predictor allows Reflected XSS. This issue affects World Cup Predi…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22794
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
579
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Ksher Ksher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ksher: from n/a through 1.1.2.
|
CWE-862
Missing Authorization
|
CVE-2025-22730
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
580
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Traveler Code. This issue affects Traveler Code: from n/a through 3.1.0.
|
CWE-89
SQL Injection
|
CVE-2025-22700
|
2025-02-5 00:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|