4291
|
3.3 |
LOW
Local
|
termius
|
termius
|
An issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES component.
|
CWE-426
Untrusted Search Path
|
CVE-2024-55503
|
2025-01-18 07:51 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4292
|
3.3 |
LOW
Local
|
phiewer
|
phiewer
|
In Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote control and unauthorized access to sensitive user data.
|
CWE-426
Untrusted Search Path
|
CVE-2024-53407
|
2025-01-18 07:51 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4293
|
6.5 |
MEDIUM
Network
|
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping …
|
CWE-89
SQL Injection
|
CVE-2024-12615
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4294
|
4.3 |
MEDIUM
Network
|
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versi…
|
CWE-862
Missing Authorization
|
CVE-2024-12614
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4295
|
7.5 |
HIGH
Network
hirewebxperts
|
passwords_manager
|
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping…
|
CWE-89
SQL Injection
|
CVE-2024-12613
|
2025-01-18 07:17 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
4296
|
- |
|
-
|
-
|
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input usin…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2025-23207
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4297
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The manipulation o…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0541
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4298
|
- |
|
-
|
-
|
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.
|
-
|
CVE-2024-57252
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4299
|
- |
|
-
|
-
|
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to
override this downgrade protection has been identified.
|
-
|
CVE-2023-50738
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
4300
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
|
-
|
CVE-2024-57372
|
2025-01-18 07:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|