1501
|
- |
|
-
|
-
|
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadPara…
|
-
|
CVE-2025-23016
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1502
|
5.3 |
MEDIUM
Network
-
|
-
|
The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including,…
|
CWE-463
|
CVE-2024-13318
|
2025-01-10 21:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1503
|
- |
|
-
|
-
|
Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.
|
-
|
CVE-2024-56113
|
2025-01-10 20:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1504
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to unauthorized modifica…
|
CWE-862
Missing Authorization
|
CVE-2024-12606
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1505
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to SQL Injection via the…
|
CWE-89
SQL Injection
|
CVE-2024-12473
|
2025-01-10 13:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1506
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
|
CWE-284
Improper Access Control
|
CVE-2025-21380
|
2025-01-10 08:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1507
|
8.8 |
HIGH
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-21385
|
2025-01-10 07:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1508
|
- |
|
-
|
-
|
In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An atta…
|
-
|
CVE-2024-55553
|
2025-01-10 07:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1509
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check
The return value of drm_atomic_get_crtc_state() …
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-56778
|
2025-01-10 06:50 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1510
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
quota: flush quota_release_work upon quota writeback
One of the paths quota writeback is called from is:
freeze_super()
sync_f…
|
NVD-CWE-noinfo
|
CVE-2024-56780
|
2025-01-10 06:50 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|