771
|
3.3 |
LOW
Local
|
phiewer
|
phiewer
|
In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
|
CWE-426
Untrusted Search Path
|
CVE-2024-53407
|
2025-01-18 07:51 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
772
|
6.5 |
MEDIUM
Network
|
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping …
|
CWE-89
SQL Injection
|
CVE-2024-12615
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
773
|
4.3 |
MEDIUM
Network
|
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versi…
|
CWE-862
Missing Authorization
|
CVE-2024-12614
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
774
|
7.5 |
HIGH
Network
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping…
|
CWE-89
SQL Injection
|
CVE-2024-12613
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
775
|
- |
|
-
|
-
|
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input usin…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2025-23207
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
776
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The manipulation o…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0541
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
777
|
- |
|
-
|
-
|
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.
|
-
|
CVE-2024-57252
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
778
|
- |
|
-
|
-
|
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to
override this downgrade protection has been identified.
|
-
|
CVE-2023-50738
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
779
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
|
-
|
CVE-2024-57372
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
780
|
- |
|
-
|
-
|
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a …
|
-
|
CVE-2024-52870
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|