51
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13401
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
52
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for_paypal' shortcode in all versions up to, and including, 1.0.32 due to insuffic…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13398
|
2025-01-17 14:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
53
|
4.0 |
MEDIUM
Local
|
-
|
-
|
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
New
|
CWE-471
Modification of Assumed-Immutable Data (MAID)
|
CVE-2024-51462
|
2025-01-17 12:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
54
|
- |
|
-
|
-
|
A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.
Update
|
-
|
CVE-2024-12806
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
55
|
- |
|
-
|
-
|
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
Update
|
-
|
CVE-2024-12805
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
56
|
- |
|
-
|
-
|
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.
Update
|
-
|
CVE-2024-12803
|
2025-01-17 12:15 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
57
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../…
New
|
CWE-22
Path Traversal
|
CVE-2024-52363
|
2025-01-17 11:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
58
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-21325
|
2025-01-17 10:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
59
|
- |
|
-
|
-
|
Fuji Electric Alpha5 SMART
is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-34579
|
2025-01-17 10:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
60
|
- |
|
-
|
-
|
librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions u…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23201
|
2025-01-17 08:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|