Latest CVE Feed
-
8.8
HIGHCVE-2025-0447
Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0446
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-0443
Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Mediu... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-0442
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-0441
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-0440
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-0439
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Race Condition
-
8.8
HIGHCVE-2025-0438
Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0437
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0436
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0435
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-0434
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
5.2
MEDIUMCVE-2025-0193
A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administ... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-35280
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3.x all versions, 4.x all versions, 5.0 all versions, 5.1 all versions, version 5.2.0, and version 5.3.0 may allow an attacker to perform a re... Read more
Affected Products : fortideceptor- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-9636
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible... Read more
Affected Products : comboblocks- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-13351
The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions up to, and including, 5.20 due to insufficient input sanitization and output... Read more
Affected Products : repuso- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12818
The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' shortcode in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12423
The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes i... Read more
Affected Products : contact_form_7_redirect_\&_thank_you_page- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12403
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'awsmgallery' parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This ... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.2
CRITICALCVE-2024-12297
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementatio... Read more
Affected Products : pt-7728_firmware- Published: Jan. 15, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Authentication