481
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver …
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22267
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
482
|
- |
|
-
|
-
|
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is kn…
New
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2025-22150
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
483
|
- |
|
-
|
-
|
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a page or comment to trigger a stored XSS which wil…
New
|
-
|
CVE-2025-24018
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
484
|
- |
|
-
|
-
|
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg.
Update
|
-
|
CVE-2024-57023
|
2025-01-22 03:15 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
485
|
7.5 |
HIGH
Network
blackberry
|
qnx_software_development_platform
|
Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the imag…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-48855
|
2025-01-22 03:07 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
486
|
7.5 |
HIGH
Network
blackberry
|
qnx_software_development_platform
|
Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image …
Update
|
CWE-193
Off-by-one Error
|
CVE-2024-48854
|
2025-01-22 03:07 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
487
|
7.5 |
HIGH
Network
blackberry
|
qnx_software_development_platform
|
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-48857
|
2025-01-22 03:06 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
488
|
9.8 |
CRITICAL
Network
blackberry
|
qnx_software_development_platform
|
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the pr…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-48856
|
2025-01-22 03:06 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
489
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_designer
|
Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21139
|
2025-01-22 02:50 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
490
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_designer
|
Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2025-21138
|
2025-01-22 02:49 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|