311
|
8.8 |
HIGH
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate p…
|
NVD-CWE-noinfo
|
CVE-2024-57726
|
2025-01-17 06:22 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
312
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kopatheme Kopa Nictitate Toolkit allows Stored XSS.This issue affects Kopa Nictitate Toolkit: fro…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23965
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
313
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Sven Hofmann & Michael Schoenrock Mark Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark Posts: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2025-23963
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
314
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Goldstar Goldstar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Goldstar: from n/a through 2.1.1.
|
CWE-862
Missing Authorization
|
CVE-2025-23962
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
315
|
- |
|
-
|
-
|
Missing Authorization vulnerability in WP Tasker WordPress Graphs & Charts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n…
|
CWE-862
Missing Authorization
|
CVE-2025-23961
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
316
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Sur.ly Sur.ly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sur.ly: from n/a through 3.0.3.
|
CWE-862
Missing Authorization
|
CVE-2025-23957
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
317
|
- |
|
-
|
-
|
Missing Authorization vulnerability in xola.com Xola allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xola: from n/a through 1.6.
|
CWE-862
Missing Authorization
|
CVE-2025-23955
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
318
|
- |
|
-
|
-
|
Missing Authorization vulnerability in AWcode & KingfisherFox Salvador – AI Image Generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salvador – AI Im…
|
CWE-862
Missing Authorization
|
CVE-2025-23954
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
319
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DivEngine Gallery: Hybrid – Advanced Visual Gallery allows Stored XSS.This issue affects Gallery:…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23951
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
320
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Said Shiripour EZPlayer allows Stored XSS.This issue affects EZPlayer: from n/a through 1.0.10.
|
CWE-79
Cross-site Scripting
|
CVE-2025-23950
|
2025-01-17 06:15 |
2025-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|