-
CVE-2025-23362 – Adobe EXIF Viewer Classic Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-23362 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed…
-
CVE-2025-0806 – Code-projects Job Recruitment Cross Site Scripting Vulnerability
CVE ID : CVE-2025-0806 Published : Jan. 29, 2025, 3:15 a.m. | 3 hours, 46 minutes ago Description : A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack…
-
CVE-2025-0802 – SourceCodester Best Employee Management System Remote Improper Access Control Vulnerability
CVE ID : CVE-2025-0802 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls.…
-
CVE-2025-0803 – Codezips Gym Management System SQL Injection Vulnerability
CVE ID : CVE-2025-0803 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection.…
-
CVE-2025-0800 – SourceCodester Online Courseware Cross Site Scripting
CVE ID : CVE-2025-0800 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting.…
-
CVE-2025-0798 – MicroWorld eScan Antivirus os Command Injection Vulnerability
CVE ID : CVE-2025-0798 Published : Jan. 29, 2025, 2:15 a.m. | 5 hours, 44 minutes ago Description : A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command…
-
CVE-2024-40672 – Samsung Android ChooserActivity Java Missing Permission Check Privilege Escalation Vulnerability
CVE ID : CVE-2024-40672 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
-
CVE-2024-40677 – Samsung AdvancedPowerUsage Denial of Service Local Privilege Escalation
CVE ID : CVE-2024-40677 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
-
CVE-2024-40669 – Apache TBD Heap Use-After-Free Local Privilege Escalation Vulnerability
CVE ID : CVE-2024-40669 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Severity:…
-
CVE-2024-40670 – Adobe Reader Use After Free (Local Privilege Escalation)
CVE ID : CVE-2024-40670 Published : Jan. 28, 2025, 8:15 p.m. | 11 hours, 44 minutes ago Description : In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Severity:…