151
|
- |
|
-
|
-
|
Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP…
New
|
-
|
CVE-2025-0354
|
2025-01-15 17:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
152
|
- |
|
-
|
-
|
A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from …
New
|
-
|
CVE-2024-7322
|
2025-01-15 17:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
153
|
7.5 |
HIGH
Network
-
|
-
|
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.
New
|
CWE-834
Excessive Iteration
|
CVE-2024-4227
|
2025-01-15 17:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
154
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-11870
|
2025-01-15 17:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
155
|
- |
|
-
|
-
|
A flaw was found in the rsync daemon which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison betwe…
New
|
-
|
CVE-2024-12085
|
2025-01-15 16:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
156
|
- |
|
-
|
-
|
Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file which is specially crafted by an attacker, arbitrary code may be executed. As a r…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2024-55577
|
2025-01-15 15:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
157
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortcode in all versions up to, and including, 1.4.15 due to insufficient input sanit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-13394
|
2025-01-15 15:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
158
|
- |
|
-
|
-
|
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
New
|
-
|
CVE-2025-23061
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
159
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-22394
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
160
|
- |
|
-
|
-
|
Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability.
A local malicious user could potentially exploit this vulnerability during installation, leading to arbitrary…
New
|
CWE-362
Race Condition
|
CVE-2025-21101
|
2025-01-15 14:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|