311
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlTi5 AlT Report allows Reflected XSS.This issue affects AlT Report: from n/a through 1.12.0.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23432
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
312
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager allows Reflected XSS.This issue affects Mass Custom Fields Manager: from n/a through 1.5.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23430
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
313
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in altimawebsystems.com Altima Lookbook Free for WooCommerce allows Reflected XSS.This issue affects…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23429
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
314
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Wizcrew Technologies go Social allows Stored XSS.This issue affects go Social: from n/a through 1.0.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23426
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
315
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Brian Novotny – Creative Software Design Solutions Marquee Style RSS News Ticker allows Cross Site Request Forgery.This issue affects Marquee Style …
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23424
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
316
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Smackcoders SendGrid for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a t…
New
|
CWE-862
Missing Authorization
|
CVE-2025-23423
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
317
|
- |
|
-
|
-
|
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is h…
New
|
CWE-200
Information Exposure
|
CVE-2024-56136
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
318
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource owners can return la…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2024-52791
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
319
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private net…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-52602
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
320
|
- |
|
-
|
-
|
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may upload a file which…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-56515
|
2025-01-17 05:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|