1521
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook allows Reflected XSS. This issue affects Nature FlipBook: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23454
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1522
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Widget Options Team Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Widget Options: from n/a through …
|
CWE-862
Missing Authorization
|
CVE-2025-22722
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1523
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apply…
|
CWE-862
Missing Authorization
|
CVE-2025-22721
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1524
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita.com Online Payments – Get Paid with PayPal, Square & Stripe allows Stored XSS. This issue a…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22661
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1525
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enguerran Weiss Related Post Shortcode allows Stored XSS. This issue affects Related Post Shortco…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22276
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1526
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver …
|
CWE-79
Cross-site Scripting
|
CVE-2025-22267
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1527
|
- |
|
-
|
-
|
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is kn…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2025-22150
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1528
|
- |
|
-
|
-
|
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a page or comment to trigger a stored XSS which wil…
|
-
|
CVE-2025-24018
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1529
|
- |
|
-
|
-
|
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
|
-
|
CVE-2024-57023
|
2025-01-22 03:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1530
|
7.5 |
HIGH
Network
blackberry
|
qnx_software_development_platform
|
Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the imag…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-48855
|
2025-01-22 03:07 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|