91
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_stager
|
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21131
|
2025-01-18 05:37 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
92
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_stager
|
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21130
|
2025-01-18 05:37 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
93
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_stager
|
Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21129
|
2025-01-18 05:37 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
94
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_stager
|
Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21128
|
2025-01-18 05:37 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
95
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
New
|
CWE-284
Improper Access Control
|
CVE-2025-21185
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
96
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulati…
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0536
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
97
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.
New
|
-
|
CVE-2024-57370
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
98
|
- |
|
-
|
-
|
Clickjacking vulnerability in typecho v1.2.1.
New
|
-
|
CVE-2024-57369
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
99
|
- |
|
-
|
-
|
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
New
|
-
|
CVE-2024-57034
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
100
|
- |
|
-
|
-
|
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing a…
New
|
-
|
CVE-2024-57032
|
2025-01-18 05:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|