1481
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS…
|
-
|
CVE-2025-23072
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1482
|
- |
|
-
|
-
|
Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This is…
|
CWE-20
Improper Input Validation
|
CVE-2025-23041
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1483
|
7.8 |
HIGH
Local
|
-
|
-
|
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the sear…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-21127
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1484
|
- |
|
-
|
-
|
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) …
|
CWE-285
Improper Authorization
|
CVE-2025-23042
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1485
|
7.8 |
HIGH
Local
|
-
|
-
|
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current …
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2025-21122
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1486
|
- |
|
-
|
-
|
Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user.
This issue affects Invoice Ninj…
|
-
|
CVE-2025-0474
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1487
|
- |
|
-
|
-
|
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…
|
-
|
CVE-2024-56374
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1488
|
- |
|
-
|
-
|
Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is text-based over standard input/output, and consists…
|
CWE-200
Information Exposure
|
CVE-2024-50338
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1489
|
- |
|
-
|
-
|
Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to a…
|
CWE-94 CWE-502
Code Injection Deserialization of Untrusted Data
|
CVE-2024-49375
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1490
|
- |
|
-
|
-
|
.NET Elevation of Privilege Vulnerability
|
CWE-379
Creation of Temporary File in Directory with Incorrect Permissions
|
CVE-2025-21173
|
2025-01-15 04:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|