Latest CVE Feed
-
8.8
HIGHCVE-2025-0437
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0436
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-0435
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-0434
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jan. 15, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Memory Corruption
-
5.2
MEDIUMCVE-2025-0193
A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administ... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-35280
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiDeceptor 3.x all versions, 4.x all versions, 5.0 all versions, 5.1 all versions, version 5.2.0, and version 5.3.0 may allow an attacker to perform a re... Read more
Affected Products : fortideceptor- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-9636
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible... Read more
Affected Products : comboblocks- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-13351
The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions up to, and including, 5.20 due to insufficient input sanitization and output... Read more
Affected Products : repuso- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12818
The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' shortcode in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12423
The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping. This makes i... Read more
Affected Products : contact_form_7_redirect_\&_thank_you_page- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12403
The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'awsmgallery' parameter in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This ... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.2
CRITICALCVE-2024-12297
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementatio... Read more
Affected Products : pt-7728_firmware- Published: Jan. 15, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-10775
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.4.32 via the 'pafe-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possi... Read more
Affected Products : piotnet_addons- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-0356
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-0355
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-0354
Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlie... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.8
MEDIUMCVE-2024-7322
A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is received, this change in node ID causes Denial of Service (DoS). To recover from this DoS, the network must be re-established... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-4227
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.... Read more
Affected Products : gsoap- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2024-11870
The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products : event_registration_calendar_by_vcita- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2024-55577
Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file which is specially crafted by an attacker, arbitrary code may be executed. As a result, the attacker may obtain or alter information of t... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Memory Corruption