1601
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light allows Reflected XSS.This issue affects Widgetize Pages Light: fr…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22313
|
2025-01-10 01:16 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1602
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeAstrology Team Product Table for WooCommerce allows Reflected XSS.This issue affects Product …
|
CWE-79
Cross-site Scripting
|
CVE-2025-22307
|
2025-01-10 01:16 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1603
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto allows S…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22295
|
2025-01-10 01:16 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1604
|
- |
|
-
|
-
|
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` and potentially lead to code execution.
|
-
|
CVE-2024-53706
|
2025-01-10 01:16 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1605
|
- |
|
-
|
-
|
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive informa…
|
-
|
CVE-2024-53522
|
2025-01-10 01:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1606
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset
The at_xdmac_memset_create_desc may return NULL, which will…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-56767
|
2025-01-10 01:16 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1607
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
Syzbot reports [1] an uninitialized value issue found by K…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-56769
|
2025-01-10 01:16 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1608
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mtd: rawnand: fix double free in atmel_pmecc_create_user()
The "user" pointer was converted from being allocated with kzalloc() t…
|
CWE-415
Double Free
|
CVE-2024-56766
|
2025-01-10 01:16 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1609
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Prevent bad count for tracing_cpumask_write
If a large count is provided, it will trigger a warning in bitmap_parse_user…
|
NVD-CWE-noinfo
|
CVE-2024-56763
|
2025-01-10 01:16 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1610
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
x86/fred: Clear WFE in missing-ENDBRANCH #CPs
An indirect branch instruction sets the CPU indirect branch tracker
(IBT) into WAIT…
|
NVD-CWE-noinfo
|
CVE-2024-56761
|
2025-01-10 01:16 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|