1491
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is ser…
|
CWE-79
Cross-site Scripting
|
CVE-2025-23366
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1492
|
- |
|
-
|
-
|
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary…
|
-
|
CVE-2025-23052
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1493
|
- |
|
-
|
-
|
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to…
|
-
|
CVE-2025-23051
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1494
|
6.4 |
MEDIUM
Network
|
-
|
-
|
On-Premises Data Gateway Information Disclosure Vulnerability
|
CWE-863
Incorrect Authorization
|
CVE-2025-21403
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1495
|
7.8 |
HIGH
Local
|
-
|
-
|
Microsoft Office OneNote Remote Code Execution Vulnerability
|
CWE-641
Improper Restriction of Names for Files and Other Resources
|
CVE-2025-21402
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1496
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**…
|
CWE-862
Missing Authorization
|
CVE-2025-23025
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1497
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).Th…
|
-
|
CVE-2025-23080
|
2025-01-15 03:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1498
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Windows SmartScreen Spoofing Vulnerability
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2025-21314
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1499
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Windows Security Account Manager (SAM) Denial of Service Vulnerability
|
CWE-833
Deadlock
|
CVE-2025-21313
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1500
|
2.4 |
LOW
Physics
|
-
|
-
|
Windows Smart Card Reader Information Disclosure Vulnerability
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-21312
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|